SafePal breach exposes addresses of 39,798 crypto wallet buyers, no funds touched
The SafePal crypto wallet maker says a third-party plug-in exposed the names, physical addresses and contact details of nearly 40,000 customers, while funds and private keys remained secure.
SafePal, the Binance-backed cryptocurrency wallet company, disclosed on August 17, 2026, that a data breach affected approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The incident exposed customer names, physical addresses and contact information, but the company said it did not compromise cryptocurrency holdings or wallet credentials.
For users of the SafePal crypto wallet, the distinction is significant. The breach did not expose passwords, private keys, seed phrases, bank information, payment-card details or government-issued identification, according to the company’s disclosure. As a result, customers’ digital assets were not directly accessible through the compromised information.
“authorization flaw” — SafePal, describing the vulnerability in the third-party plug-in used for order tracking.
The company said the vulnerability allowed attackers to access other customers’ order details by manipulating order numbers. The incident therefore involved the e-commerce infrastructure surrounding the SafePal crypto wallet rather than the underlying wallet security mechanisms protecting users’ funds.
SafePal has previously emphasized that its wallet architecture is designed to keep users in control of their private keys. The company says its hardware wallets use security mechanisms intended to protect sensitive wallet information, while its broader product ecosystem is built around non-custodial asset management.
SafePal crypto wallet users face a different kind of risk
While no cryptocurrency was reportedly stolen in the breach, the exposure of customer addresses could create a different security problem for SafePal crypto wallet users.
A database containing the names, contact information and delivery addresses of people who purchased cryptocurrency wallets can provide criminals with valuable intelligence. Unlike a conventional retail customer database, such information may identify people who are likely to own or manage digital assets.
The most immediate concern is targeted phishing. Attackers with access to a customer’s name, address and order information could craft more convincing messages impersonating SafePal, delivery companies, cryptocurrency platforms or customer-support representatives.
That makes the exposed information potentially useful for social-engineering attacks. A phishing message that references a genuine purchase can appear substantially more credible than a generic scam email.
The risk extends beyond digital deception. Cryptocurrency holders have increasingly faced physical security threats, including robberies and coercion aimed at forcing victims to surrender access to their assets. Such attacks are sometimes described in the cryptocurrency industry as “wrench attacks.”
For a SafePal crypto wallet customer, therefore, the exposure of a home address cannot necessarily be treated as a minor privacy incident. Unlike a password, an address cannot simply be changed or reset after a breach.
SafePal crypto wallet maker says vulnerability was patched
SafePal said it responded quickly after discovering the issue. The company attributed the breach to a third-party plug-in responsible for order tracking and said the vulnerability was patched immediately.
The company also said it had commissioned an independent third-party auditor to examine the incident and had reduced its data-retention period to 90 days.
In addition, SafePal said it identified and removed more than 30 fraudulent websites and phishing links. Affected customers were contacted through the company’s security email address and were provided with a mechanism to determine whether their information was included in the exposed data.
“no cryptocurrency funds were touched” — SafePal, in its disclosure of the incident.
The company’s response highlights an important distinction in cryptocurrency security: protecting the wallet itself does not necessarily protect every system connected to the wallet business.
The SafePal crypto wallet infrastructure may have kept private keys and digital assets isolated from the compromised system, but the order-tracking component still provided attackers with access to sensitive customer information.
That separation is increasingly important as cryptocurrency companies rely on third-party services for ecommerce, analytics, customer management, logistics and other functions.
The incident also underscores the growing security challenge posed by third-party software.
A company’s core infrastructure can remain secure while an external plug-in, integration or service exposes customer data. In this case, the compromised component was associated with order tracking rather than the wallet’s cryptographic security.
For SafePal crypto wallet customers, that distinction offers some reassurance but does not eliminate the need for caution.
SafePal has advised affected users through its security communications, while the company says it has taken steps to limit future exposure. Its broader security documentation also emphasizes the importance of protecting recovery seeds and using secure wallet practices.
“Safety is proactive.” — SafePal, describing one of its core security values.
The breach demonstrates why that principle extends beyond private keys and blockchain transactions. In a crypto ecosystem, personal information can itself become a security asset for criminals.
The immediate outcome is therefore mixed. The SafePal crypto wallet appears, based on the company’s account, to have protected customers’ funds and critical wallet credentials from the breach. However, the exposure of nearly 40,000 customers’ identities and physical addresses creates a potentially serious privacy and social-engineering risk.
For those affected, vigilance around unexpected emails, messages, calls, delivery notifications and requests for wallet credentials will be particularly important. Customers should also treat any request for a seed phrase, private key or wallet password as suspicious, regardless of how much personal information the sender appears to know.
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.