Data BreachBleeping Computer
4.5 — MEDIUM
SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A data breach at SafePal cryptocurrency hardware wallet provider exposed approximately 39,798 customers' order information, including names, email addresses, shipping addresses, and phone numbers, which is now being sold on a cybercrime forum.
⚙️Technical Details
Affected Systems
SafePal's e-commerce systema plug-in that allowed unauthorized access to another customer's order information
Attack Vectors
authorization flaw in the order-tracking function of the plug-inconfiguration error that caused a data-cleanup process to stop functioning correctly
💥Impact Assessment
Severity: medium
Who Is at Risk
SafePal customers who placed orders between March 2, 2025, and April 11, 2026
🛡️Recommended Actions
1Customers should watch for targeted phishing emails and phone calls about firmware upgrades, product returns, refunds, or legal investigations.
2Customers whose order information was exposed do not need to replace their hardware wallets or move cryptocurrency because of the breach.
3Customers who already shared their seed phrases or private key in response to a phishing email or text should treat their wallet as compromised and transfer any assets to a new wallet on a trusted SafePal device or official application.
📦Affected Products
SafePal's e-commerce systemthe plug-in that allowed unauthorized access to another customer's order information
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
