SafePal Reports Data Breach Affecting 39,798 Customers After Authorization Error
An authorization error in an order plugin exposed names, addresses, and contact details for nearly 40,000 SafePal customers; wallets and private keys were not affected.

Key Takeaways
- SafePal reported a data breach in which personal data from 39,798 customers was exposed because of an authorization error in an order plugin.
- Names, addresses, and contact details were affected, but crypto assets, passwords, private keys, and seed phrases were not.
- SafePal patched the vulnerability, informed customers, and took extra steps against phishing and fraudulent websites.
SafePal reported a security incident in which personal data from 39,798 customers was exposed. According to the crypto company, this involved names, physical addresses, and contact details, while crypto assets, passwords, and private wallet keys were not affected.
What Exactly Went Wrong
The incident was caused by an authorization error in a plugin that tracks customer orders. As a result, attackers may have been able to view other customers' orders by changing order numbers. SafePal said the leak affects customers who placed an order between March 2, 2025 and April 11, 2026.
The announcement matters because hardware wallets are often seen as one of the safer ways to store crypto, but operational systems can still be a weak spot there too. SafePal stressed that the core security of the wallets remained intact and that seed phrases, private keys, bank details, payment card numbers, and identity documents were not affected.
Phishing Risk
For affected users, the biggest risk now is mainly phishing and impersonation. With names, addresses, and contact details, bad actors can more convincingly pretend to be SafePal or another party. SafePal also warned that users who have ever shared their private keys or seed phrases through a phishing email, phone call, or letter should consider their wallet compromised.
The company says it has patched the vulnerability and added extra security measures. SafePal has also informed all affected customers by email, brought in an independent security firm to review the fix and order processing, and removed more than 30 fraudulent websites and phishing links.
Why This Matters for Users
For European crypto users, this incident shows that the biggest risks are not always in the wallet itself, but also in the systems around it. According to the available information, SafePal has an S1 model with air-gap technology and a secure element chip, but that does not change the fact that order data and customer communication can still be targeted. That makes a good separation between crypto storage and sharing personal information even more important.
SafePal also says it will now keep customer data in the order processing system for only 90 days. The company also offers a verification tool that lets customers check whether their data was affected.