- A vulnerability in Safepal’s order‑tracking plug‑in exposed the personal data of almost 40,000 customers.
- The company said the breach did not reveal wallet credentials, but it does leave users open to targeted phishing attempts.
Following Trezor’s disclosure of a leak affecting more than 13,600 customers in seven countries due to a compromised shipping provider, another hardware wallet maker warned users of a comparable issue. Safepal, a non‑custodial crypto wallet suite backed by Binance, reported a security incident that exposed the sensitive information of 39,798 users.
The Safepal Data Leak
Safepal explained that an “authorization flaw in the order‑tracking function of a plug‑in handling customer order information” led to the large‑scale data leak. Although it did not name the compromised tool, the company said the flaw allowed customers to view each other’s order details. This opened unauthorized access to names, phone numbers, email addresses, receiving addresses, purchase dates and other personal data.
The firm added that the plug‑in exploit affected orders placed between March 2 2025 and April 11 2026. The timeframe matches a recurring complaint from buyers who said they had received numerous phishing attempts from individuals posing as Safepal representatives.
Increased Safepal Phishing Attempts
In most cases, the attackers urged users to update their hardware wallets to supposedly fix a firmware‑level security vulnerability. It is unclear how many fell for the scam, but recipients reported that the callers sounded convincing, especially because they possessed specific details about the users’ Safepal purchases.
Despite this, Safepal assured the public that the incident did not expose seed phrases, private keys, wallet passwords or other wallet credentials, since it does not collect, store or process such sensitive information. Consequently, it advised users never to share those details with anyone, even callers claiming to be from the company.
Safepal acknowledged that the problem indeed exposed affected customers to targeted phishing and impersonation attempts. It urged them to stay vigilant and to disregard calls, emails, letters, text messages, refund offers, firmware‑update requests or any communication asking for wallet credentials or additional personal information.
Issue Patched
Safepal assured customers that it had already fixed the flaw and strengthened its security measures after discovering the incident. It also engaged an independent third‑party firm to conduct security audits of its systems as an added precaution and to uncover any other hidden vulnerabilities.
Furthermore, the company said it now limits the retention period for customer orders to 90 days and has taken down more than 30 websites associated with Safepal impersonators.
What’s your Reaction?
+1
1
+1
0
+1
0
+1
0
+1
0
+1
0
+1
0
Also Read
- Study Suggests AI Agents Account for Minimal Share of Crypto Payments
- EU Mandates 24-Hour Reporting for Exploited Vulnerabilities in Connected Crypto Wallets
- AMC CEO Denounces Robinhood’s Tokenized Shares as Undermining Investor Protections
- Ringgit Forecast to Trade in Narrow Band Near RM4.06-RM4.08 Next Week


