VERSE PRESS

Crypto News, Global First.

SafePal Data Breach Exposes Nearly 40,000 Customers' Personal Information

Crypto hardware wallet provider SafePal disclosed on August 16 that unauthorized parties accessed personal data belonging to 39,798 customers, with phishing attacks exploiting the stolen information already underway for weeks before the company went public.

|

The breach affected orders placed between March 2, 2025, and April 11, 2026. Exposed data includes full names, email addresses, phone numbers, physical shipping addresses, and purchase details such as order numbers, amounts, and product models. SafePal was explicit about what was not compromised: seed phrases, private keys, wallet passwords, payment card numbers, bank account details, and government-issued ID numbers were not accessed. As security analysts have noted, for hardware wallet users those credentials are the keys to actual funds, and their absence from the breach limits direct financial exposure. Even so, the personal data that was stolen is more than enough to run convincing fraud campaigns.

SafePal, incubated by Binance Labs and serving more than 30 million users across 200+ countries, traced the intrusion to an authorization flaw in a third-party order-tracking plugin, one that allowed unauthorized parties to view other customers' order records under certain conditions. SafePal says it has since patched the vulnerability, updated its data retention policy to a 90-day window, and taken down more than 30 fraudulent websites and phishing links connected to the incident.

Affected customers received notification emails from security@safepal.com on the day of disclosure.

Customers Were Being Targeted Weeks Before the Warning

The timeline raises serious questions about SafePal's response speed. According to reporting by The Block, customers began flagging phishing emails as early as July 2026, weeks before the official August 16 disclosure.

Those messages arrived from a safepal.review domain and quoted accurate order details including order number, date, amount, billing address, and payment method.

That level of specificity strongly suggests the breach data was being actively used before SafePal had alerted its user base. Customers in markets with limited consumer protection enforcement had no formal warning during that window.

One analyst report from Startup Fortune noted that SafePal's initial public framing described it as a "decentralized wallet" without access to payment or personal data. The report argued this framing sidestepped accountability by conflating asset custody with customer data responsibility: the company does collect and store customer fulfillment data, and that data was exposed. The same report argued that "hardware wallet companies now face bank-level expectations for data stewardship," extending beyond cryptographic security to include vendor management, fulfillment practices, and incident disclosure timelines.

Third-Party Plugin Risk Is a Known and Recurring Problem

The attack vector here is not novel. In 2020, Ledger suffered a data breach through its e-commerce partner Shopify that exposed nearly 300,000 users' personal information, triggering years of phishing campaigns and even reports of counterfeit Ledger devices shipped to victims' homes.

In January 2026, Ledger was hit again, this time through payment processor Global-e, with customer names, emails, physical addresses, and phone numbers exposed.

The SafePal incident follows the same pattern: the wallet's cryptographic layer holds, but the surrounding commercial infrastructure becomes the attack surface. For developers integrating third-party logistics or CRM plugins into crypto-adjacent commerce, this breach is a direct cautionary case.

Regional Users Face Elevated Risk

SafePal serves more than 30 million users across 200+ countries, and the breach carries particular weight in regions where the company has built significant retail adoption. In Southeast Asia, Indonesian investment platform Pluang ran dedicated coverage of the incident, reflecting real concern among retail users in one of the world's largest crypto markets.

In South Asia, users in India and Pakistan rely heavily on hardware wallets for self-custody in environments where banking access is uneven and remittance activity is high. Phone number and home address exposure in these markets creates direct risk of WhatsApp and SMS impersonation attacks, a common and effective fraud vector.

In Africa, where Nigeria, Kenya, Ghana, and South Africa represent fast-growing segments of hardware wallet adoption, the stakes are compounded further. Nigeria alone recorded the world's second-highest crypto adoption rate in 2025 per Chainalysis's Global Crypto Adoption Index. In markets where peer-to-peer crypto trading is dominant and digital verification infrastructure is limited, fraudsters can use real order data to impersonate support agents with credibility that is difficult for targets to challenge. The risk extends further given Africa's growing integration of mobile money networks with crypto wallets: the April 2026 partnership between VALR and Onafriq illustrates how breached personal data can be leveraged across both ecosystems simultaneously.

Token Markets, Immediate Steps, and What Comes Next

SafePal's native token, SFP, used for platform governance and fee discounts, was trading at approximately $0.23 at the time of disclosure, with a market cap in the range of $115 million to $131 million. The daily price move of roughly negative 2 percent tracked broader market trends rather than signaling breach-specific selling pressure.

SafePal advises all affected users to treat any inbound communication referencing order details as suspicious, regardless of how accurate those details appear. Users should not respond to any email, SMS, or call referencing SafePal order details even if the information appears accurate. Those in South Asian and African markets should be specifically alert to WhatsApp-based impersonation, a vector that security researchers flag as particularly effective in these regions. Users who have shared seed phrases or private keys with any party since July 2026 should transfer assets to a new wallet immediately. The company's verification tool, available at safepal.com, allows users to check whether their account was included in the 39,798 affected records.

The broader pattern across Ledger, Trezor (which issued customer alerts following a third-party breach affecting contact information in 2024), Coldcard (whose July 2026 vulnerability exposed approximately $116 million across more than 5,200 addresses and contributed to roughly $247 million stolen that month), and now SafePal points to a structural gap in the hardware wallet industry. Cryptographic security is treated as a primary concern, while the data practices of the commercial operations surrounding it receive far less scrutiny.

With phishing losses across the crypto sector reaching roughly $84 million in 2025, and AI-generated attacks making stolen order data more effective than ever per Chainalysis's 2026 Crypto Crime Report, that gap is becoming harder to ignore. Phishing and impersonation scams surged approximately 1,400 percent year over year across 2025 and 2026, according to Ledger Academy, underscoring how dramatically the threat landscape has shifted.