Cybersecurity

SafePal Data Breach Affects Approximately 39,798 Customers, Information Offered for Sale on Criminal Forum

SafePal warned that order data belonging to approximately 39,798 customers was leaked following the exploitation of a flaw in the order-tracking function, while an attacker claims to be offering the data for sale. According to the company, the incident did not include wallet keys, recovery phrases, or payment data.

2026-08-16
4 min read
11 views
فريق تحرير certi.news
SafePal Data Breach Affects Approximately 39,798 Customers, Information Offered for Sale on Criminal Forum

SafePal, a provider of cryptocurrency hardware wallets, announced a data breach affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The company said the flaw was exploited to gain unauthorized access to order information, while a threat actor currently claims to be offering the stolen data for sale on a cybercrime forum.

The affected data includes customers’ names, email addresses, shipping addresses, phone numbers, and purchase information. SafePal confirmed that its investigation found no evidence that wallet recovery phrases, private keys, passwords, bank account information, bank card numbers, government-issued identity documents, or other credentials were exposed.

Order-tracking flaw led to unauthorized access

SafePal discovered the issue during a comprehensive review and reconstruction of its order-processing system that it began in July. The company concluded that an authorization flaw in the order-tracking function of one of its plugins allowed access to other customers’ order information.

The company received a report consistent with the incident in early May 2026, but initially treated it as an isolated case before escalating it to a formal security investigation and adding further safeguards. Because of the interconnectedness of the e-commerce system’s components, external integrations, and logistics service providers, SafePal said it was unable to immediately rule out several possible explanations.

During the investigation, the company also discovered a separate configuration error that prevented the data-cleanup process from operating correctly between September 2025 and April 2026, resulting in the retention of order data dating back to March 2025. It said it fixed the flaw and implemented additional security measures, and is working with an external security company to verify the fix and conduct a broader review of its order-processing systems.

What changes practically for customers?

On August 16, SafePal sent an email to all affected customers with a subject line warning that order information had been affected. It also launched an online verification tool that allows customers to enter their order number and shipping country to find out whether that order’s data is among the stolen information.

The company warns that the data may be used in phishing messages and targeted calls concerning firmware updates, product returns, refunds, or legal investigations. Customers have reported phishing messages and calls since May, including a message claiming that a vulnerability had been discovered in a SafePal X1 wallet and requesting installation of a firmware update. The company said it removed more than 30 fraudulent websites and links associated with the incident.

Should assets be transferred or the wallet replaced?

SafePal says customers whose order information was exposed do not need to replace their devices or transfer their cryptocurrency solely because of this leak. However, it recommends that if a customer shared their recovery phrase or private key in response to a phishing message, they should consider the wallet compromised and transfer the assets to a new wallet using a trusted SafePal device or the official app.

The company says it deleted the personal data of the affected orders from active e-commerce servers, while retaining an encrypted offline copy for possible use in law-enforcement investigations. BleepingComputer has not independently verified that the attacker possesses the data or that the sale offer is genuine, although the order-period details and the number of customers cited in the advertisement match what SafePal announced.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news