Safepal security vulnerability exposes data of 39,798 customers
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
SafePal, a crypto hardware wallet provider, disclosed a data breach exposing the names, physical addresses, and contact details of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The breach stemmed from an authorization flaw in a plug-in used to track customer orders, enabling attackers to access other customers' order information. SafePal confirmed that no cryptocurrency funds, seed phrases, private keys, bank details, or government IDs were compromised.
Why it matters
This breach highlights risks related to customer data security in the crypto industry, particularly regarding personal information that could be used for phishing and impersonation attacks. It underscores that while wallet core security may remain intact, ancillary systems like order tracking can introduce vulnerabilities. The incident reinforces the importance of assessing and diversifying crypto storage and the associated exposure to various attack vectors.
Key context
SafePal provides physical hardware wallets and software aimed at secure digital asset management. This breach follows a recent significant hack affecting Coldcard hardware wallets, where at least $120 million in bitcoin was reportedly stolen. Although these incidents do not necessarily indicate systemic hardware wallet weaknesses, they demonstrate that no crypto-storage method is without risk. SafePal responded by patching the vulnerability, notifying affected customers, and employing a third-party security audit.
Key numbers and entities
SafePal, 39,798 customers impacted, order dates March 2, 2025 to April 11, 2026. Coldcard was mentioned as a comparison relating to another recent hack involving approximately $120 million in bitcoin. SafePal communicated with customers via security@safepal.com.
What remains unclear
The source does not flag open questions but does not provide detailed information about the extent of the attackers' access beyond order data or timeline specifics of the attack discovery relative to the incident date. The effectiveness of the security measures beyond patching the identified flaw is not fully detailed.