"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal clarified.
Scale and timeline: 39,798 customers, orders placed between 2 March 2025 and 11 April 2026
SafePal told customers on 16 August that order information linked to 39,798 people was exposed in a recent breach. The company said the incident affected customers who placed orders between 2 March 2025 and 11 April 2026. The exposed records, SafePal said, contained names, email and shipping addresses, phone numbers and purchase details.
What was exposed — and what SafePal says was not
According to SafePal, the stolen data is limited to order-related personal information: names, emails, shipping addresses, phone numbers and purchase details. The company explicitly stated that the incident did not involve seed phrases, private keys, wallet passwords or other wallet credentials, nor bank account information, payment card numbers, or government‑issued identification numbers.
SafePal also said it "never requests, collects, processes or stores such information from customers" and reported finding "no evidence" that the breach itself compromised access to SafePal wallets or funds.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCause and remediation: an order‑tracking plug‑in vulnerability
SafePal attributed the breach to a defect in an order‑tracking function for a plug‑in. The firm said the flaw "under certain conditions" allowed unauthorized access to another customer's order information. SafePal said it remediated the issue upon discovery and "introduced additional security measures."
Phishing, fraud and takedowns: the immediate risks and actions
SafePal warned customers to expect a range of fraudulent approaches that attempt to convert exposed order data into further compromise. The company listed likely vectors customers should watch for: "fraudulent phone calls, emails, text messages, letters, refund offers, firmware‑update requests, fake customer‑support communications" and other solicitations designed to obtain wallet credentials or additional personal information.
The firm reported it had already taken down more than 30 fraudulent websites and phishing links associated with the incident. Screenshots posted to X show an individual offering the stolen data for sale, although SafePal noted those claims have not been verified.
SafePal has published a dedicated page for reporting scams and opened a support channel for affected customers. It issued direct guidance to users, including:
- Never share your seed phrase, private key, or password with anyone, even if they claim to be a SafePal employee.
- Don’t click links or scan QR codes in unsolicited emails, text messages, or letters claiming to be from SafePal.
- Type the SafePal web address manually into the browser rather than following a redirected link, including any link that appears to come from this notice.
- Be on the lookout for any suspicious communication or impersonation, whether by phone, post or in person.
- Report anything suspicious, including messages, calls, letters or websites.
What this means for technologists, affected customers, and takedown teams
- Technologists and security teams: verify that the remediation to the order‑tracking plug‑in fully prevents unauthorized cross‑customer access and review plug‑in and API controls tied to order information.
- Affected customers: follow SafePal's reporting page and support channel, heed the company's advice to never share wallet credentials and avoid unsolicited links or QR codes.
- Fraud‑response and takedown teams: continue monitoring and removing phishing domains and links — SafePal reports more than 30 such takedowns already — and assess the unverified sale claims appearing on X.
SafePal's public account of the incident concentrates on exposed order data and immediate fraud risks. The company asserts no wallet credentials or payment data were taken and says it has remediated the plug‑in flaw and added security measures. Still, the presence of nearly 40,000 impacted orders and reports of data being posted for sale sustain a tangible risk of targeted phishing and social‑engineering efforts; the claims of a sale on X remain unverified, and the effectiveness of the firm's additional security measures will be judged by whether further fraudulent activity appears.
https://www.infosecurity-magazine.com/news/safepal-data-breach-tens-thousands/




