Crypto wallet provider SafePal discloses data breach affecting nearly 40,000 users' order information
Crypto wallet provider SafePal disclosed a data breach that involved unauthorized access to about 39,798 customers' order information, including personal details such as names, addresses and purchase data. The breach did not involve access to seed phrases, private keys, w…
Intelligence analysis by Llama

SafePal, a cryptocurrency wallet provider, disclosed a data breach that affected nearly 40,000 users' order information. The breach occurred due to an authorization flaw in the order tracking system, which allowed access to another customer's order information between March 2, 2025, and April 11, 2026. SafePal has fixed the issue and introduced further security measures in response.
Imagine you have a digital wallet where you store your money and personal details. A company called SafePal helps people manage their digital wallets. Unfortunately, SafePal had a problem with its system that allowed someone to access some users' personal details. SafePal fixed the problem and is now being more careful with users' data.
Analysis
Data Breach Details
SafePal disclosed a data breach that involved unauthorized access to about 39,798 customers' order information, including personal details such as names, addresses and purchase data. The breach occurred due to an authorization flaw in the order tracking system, which allowed access to another customer's order information between March 2, 2025, and April 11, 2026.
Impact on Users
The breach did not involve access to seed phrases, private keys, wallet passwords, bank account and payment card information or government-issued identification numbers. However, affected users' order information could be used for targeted phishing and impersonation attempts. SafePal has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach.
SafePal's Response
SafePal has fixed the issue and introduced further security measures in response. The company will retain customers' personal data in its order processing system for only 90 days. This move demonstrates SafePal's commitment to customer security and data protection.
Key points
- SafePal disclosed a data breach that involved unauthorized access to about 39,798 customers' order information.
- The breach occurred due to an authorization flaw in the order tracking system.
- SafePal has fixed the issue and introduced further security measures in response.
- The company will retain customers' personal data in its order processing system for only 90 days.
- SafePal has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach.
SafePal's response to the breach demonstrates its commitment to customer security and data protection. The company's decision to retain customers' personal data in its order processing system for only 90 days shows that it is taking steps to prevent similar breaches in the future.
The data breach highlights the importance of secure crypto-management tools and the need for users to protect their personal data. If users are not careful, they may fall victim to targeted phishing and impersonation attempts.