Crypto wallet provider SafePal disclosed that an authorization flaw in its order-tracking system exposed the personal information of about 39,798 customers, including names, addresses, and purchase details. The company says private keys and seed phrases were unaffected, but customers reported phishing attempts tied to the exposed data as early as July.
SafePal said in a post on X on Sunday that an authorization flaw in its order-tracking system let unauthorized parties access personal data belonging to roughly 39,798 customers. The exposed records include names, email addresses, shipping addresses, phone numbers, and purchase details tied to orders placed between March 2, 2025, and April 11, 2026.
According to SafePal: "did not involve your seed phrase, private keys, wallet password, or other wallet credentials", and the company found no evidence that access to SafePal wallets or funds was compromised. The company also warned that attackers may pose as SafePal staff to push fake firmware updates, refunds, or replacement devices in an effort to obtain wallet credentials from affected users.
SafePal has not said when the flaw was introduced, when records were first accessed, or how many attackers may have obtained the data. The company did not immediately respond to questions from The Block.
Timeline of the investigation
SafePal said it received a report consistent with the breach in early May but initially treated it as an isolated case. The firm later escalated the matter and began a full review and rebuild of its order-processing pipeline in July, when it confirmed the root cause.
Public complaints predated Sunday's disclosure. A Trustpilot review dated July 4 describes scammers impersonating SafePal and citing the reviewer's account details before directing them to a fraudulent site to arrange a replacement device. A separate Reddit post from July 3 describes a caller who knew the poster's name, address, phone number, email, and prior order details. Blockchain analyst Specter first flagged both posts on X; The Block could not independently connect them to the breach.
Responding to Specter, SafePal said it carried out investigations at the time but did not discover any breaches. The company also said it has identified and taken down more than 30 fraudulent websites and phishing links tied to the scam, and it is working with asset-tracing specialists after asking affected users to report losses through its support channel.
Wallet providers face repeated data exposures
SafePal's disclosure follows two recent incidents at commerce systems used by other hardware wallet providers. On Thursday, The Block reported that a breach at Trezor's shipping partner ShipMonk exposed data belonging to nearly 14,000 customers, with names, phone numbers, and full addresses exposed for 11,742 customers and names, cities, and emails exposed for another 1,947.
SafePal called the timing of its disclosure, coming days after Trezor's, an unfortunate coincidence outside its control. In January, wallet maker Ledger notified some customers that their names and contact information had been exposed at Global-e, a third-party commerce provider handling some of its website purchases. In each case, the companies said wallets and private keys remained secure.
Source: The Block
Trading involves risk.