SafePal Security Breach Impacts 39,798 Users, Data Leaked and Allegedly Sold Online
A cryptocurrency wallet provider disclosed a data breach affecting 39,798 users, with personal and transactional information allegedly accessible to unauthorized parties.
Breach Details
The incident involved exposure of customer order data, including names, addresses, shipping details, phone numbers, and purchase records.
Vulnerability and Timeline
Vulnerability Origin
The vulnerability originated from an authorization flaw within a third-party order tracking plugin. Under specific conditions, this flaw allowed one user to access another’s order information.
Timeline of Events
The compromised data pertains to transactions conducted between March 2, 2025, and April 11, 2026. The company first received reports of the issue in early May 2026 and initially classified it as an isolated incident. Subsequent investigation confirmed the scope of the exposure, prompting a formal security review and implementation of mitigations.
Phishing Incident
Link to Breach
While no direct link has been established between the data breach and the phishing attempt, the timing and shared details align with the exposed information.
Company Response
Data Security Confirmation
Mitigation Measures
Affected users received individual notifications via email on August 16, with the subject line “[Important] Your SafePal Order Information Has Been Affected.” Mitigation measures include patching the vulnerability, engaging an external security firm for a thorough review, and reducing the retention period for personal order data to 90 days. SafePal also reported dismantling over 30 phishing sites and fraudulent links associated with the incident.
Threat Actor’s Listing
A threat actor has reportedly listed stolen data on a cybercrime forum, claiming to possess records from the SafePal breach. The listing matches the 39,798 customer count disclosed by the company. The actor offered to validate data samples using SafePal’s verification tool, specifying that potential buyers must provide a legitimate price or face rejection. As of the latest update, no independent verification confirms the authenticity of the alleged data.
Implications and Recommendations
SafePal reiterated warnings against suspicious outreach, advising users to treat unexpected communications or hardware deliveries related to their purchases as potential threats. The company emphasized ongoing monitoring for new phishing attempts and fraudulent activity. The breach highlights risks associated with third-party software vulnerabilities and the potential for exposed data to enable social engineering attacks. Organizations are encouraged to review their own supply chain security practices and implement robust monitoring for unauthorized access attempts.
