- SafePal said a plug-in flaw exposed personal data for about 39,798 customers.
- The company said wallet credentials and payment data were not involved.
- SafePal said it fixed the issue and notified affected customers.
The SafePal breach has renewed concerns around the privacy risks tied to buying hardware and self-custody wallets. SafePal said attackers gained unauthorized access to customer information through a flaw in an order-tracking plug-in, affecting about 39,798 people who placed orders between March 2, 2025, and April 11, 2026. The company said names, email addresses, shipping addresses, phone numbers, and purchase details were exposed. It also said seed phrases, private keys, wallet passwords, bank details, payment card numbers, and government IDs were not part of the incident. Even without direct wallet access, the SafePal breach has drawn attention because exposed personal data can still increase real-world security risks.
SafePal breach exposed customer order records
SafePal said in a statement on X that the issue came from an order-tracking plug-in and allowed attackers to access customer information without authorization. The company said the affected group included customers who placed orders over a period stretching from early March 2025 to mid-April 2026. It estimated that roughly 39,798 customers were affected.
According to SafePal, the exposed records included names, email addresses, shipping addresses, phone numbers, and purchase details. The company said the flaw has been fixed, affected users were contacted by email, and a page was created so customers can check whether their information was exposed. SafePal also apologized to its community and said it would continue to post updates as the investigation moves forward.
Why the SafePal breach is drawing concern
SafePal said wallet credentials were not touched, which means the incident did not directly expose seed phrases, private keys, or wallet passwords. It also said bank details, payment card numbers, and government IDs were not involved. Even so, the SafePal breach has raised concern because the leaked information can still reveal where customers live and that they bought crypto-related products.
That combination of identity and purchase data is especially sensitive in a market where some holders have faced physical threats. The source noted that criminals can use addresses and proof of crypto ownership to identify potential victims. This has become more serious as so-called wrench attacks have gained attention, with victims pressured or assaulted to hand over their assets.
SafePal breach comes amid rising physical attack fears
The broader backdrop helps explain why the SafePal breach matters beyond a standard data incident. Chainalysis documented 46 violent incidents in the first half of 2026 and said more than $30 million was stolen. It described the year as being on pace to become the worst on record, with home invasions increasingly overtaking kidnappings.
Those figures have kept the focus on how customer data leaks can create offline danger even when no funds are immediately stolen in the breach itself. In this case, names, home addresses, phone numbers, and purchase details may be enough to make some customers feel exposed. For self-custody users, privacy failures can carry consequences that go well beyond phishing emails or spam.
Other wallet firms face similar customer leaks
SafePal is the latest wallet company to face scrutiny over exposed customer information. Just days earlier, Trezor disclosed that a breach involving shipping partner ShipMonk affected data tied to roughly 13,700 customers. That case added to a growing list of incidents involving companies that sell wallets or related products.
The source pointed to Ledger as the best-known example. Ledger’s 2020 customer data leak exposed details linked to about 272,000 people and was later followed by phishing campaigns and, in some cases, ransom threats that referenced violence. Those earlier incidents remain an important reminder that leaks of customer records can have lasting effects even when core wallet systems are not compromised.
Recent security scares add pressure on self-custody users
The SafePal breach also arrived during a tense period for people who manage their own crypto storage. The report said many self-custody users were already unsettled by the Coldcard exploit, which drained long-dormant Bitcoin through a firmware entropy flaw. That event pushed industry-wide losses toward $130 million.
SafePal described itself as a non-custodial wallet suite backed by Binance and Animoca Brands, and said it serves 30 million users. Against that backdrop, this incident adds to a broader sense of strain across the wallet sector. Even though SafePal said it has fixed the plug-in issue, the breach lands at a time when users are already watching wallet security and operational safeguards more closely.
Conclusion
The SafePal breach exposed personal and order information tied to roughly 39,798 customers, but the company said seed phrases, private keys, passwords, and payment data were not affected. SafePal said the flaw came from an order-tracking plug-in, that it has fixed the issue, and that affected users were notified. Still, the SafePal breach stands out because names, addresses, phone numbers, and purchase details can create risks that extend beyond online fraud. With recent disclosures involving Trezor and the longer shadow of the Ledger leak, the incident adds to ongoing concern that wallet buyers may face privacy and physical security threats when customer records are exposed.
Disclaimer
The information provided in this article is for informational purposes only and should not be considered financial advice. The article does not offer sufficient information to make investment decisions, nor does it constitute an offer, recommendation, or solicitation to buy or sell any financial instrument. The content is opinion of the author and does not reflect any view or suggestion or any kind of advise from CryptoNewsBytes.com. The author declares he does not hold any of the above mentioned tokens or received any incentive from any company.
Featured image created by AI

