Cryptocurrency wallet provider SafePal has confirmed an authorization flaw exposed contact and order data for nearly 40,000 customers. While funds and sensitive security credentials remain secure, the company is warning users to be vigilant against potential phishing attempts.
Cryptocurrency hardware wallet provider SafePal has disclosed a security incident involving an unauthorized data exposure of its customer base. The breach, which resulted from an authorization flaw in the company’s order-tracking system, affected the personal order details of approximately 39,798 customers. This incident occurred over a period spanning March 2, 2025, to April 11, 2026.
Security of Assets and Credentials
For users and investors concerned about the safety of their digital assets, SafePal has clarified that the breach did not impact critical security credentials. Private keys, seed phrases, wallet passwords, and payment information remained encrypted and inaccessible during the incident. Consequently, there is no evidence that user funds or government-issued identification numbers were compromised. The exposure was strictly limited to contact and order-related information, such as customer names, email addresses, shipping addresses, phone numbers, and purchase history.
Remediation and Data Policy Updates
The company has since patched the authorization flaw that allowed the unauthorized access. As part of its remediation efforts, SafePal has implemented stricter internal controls and updated its data retention policy. Going forward, the company has committed to retaining customer personal information within its order-processing system for a maximum of 90 days, aiming to limit the scope of potential future data exposure.
To mitigate the risk of follow-up attacks, SafePal has taken proactive measures to identify and remove over 30 fraudulent websites and phishing links designed to impersonate the brand. The primary risk for affected users remains social engineering; individuals whose contact details were part of the exposed dataset may be targeted by attackers attempting to gain information through deceptive emails or messages.
Context and Market Sentiment
SafePal operates as a private entity and is not listed on public stock exchanges, meaning there is no corporate share price or equity filing associated with this event. However, the company is the issuer of the SFP utility token, a digital asset available on various cryptocurrency exchanges. Security incidents involving wallet providers often lead to short-term volatility in the prices of their associated tokens due to the potential reputational impact. Users and holders of the SFP token should monitor official company communications for further updates regarding the security audit and any long-term operational changes. As a standard precaution, users are advised to be skeptical of any unexpected communication requesting personal or security information, regardless of whether it appears to come from an official source.
