The hardware wallet shaper stressed that unauthorized menace actors gained entree to the information done a malfunctioning plugin utilized to way users’ orders. The incident, which transpired betwixt March 2, 2025 and April 11, 2026, leaves users susceptible to phishing attacks and fraudulent telephone calls.
Key Takeaways
- Safepal suffered a information breach exposing the idiosyncratic details and shipping addresses of 39,798 users.
- While wallet keys stay safe, the leaked addresses permission users susceptible to carnal wrench attacks.
- Safepal secured the flaw but faces harsh disapproval for delaying disclosure contempt anterior scam reports.
Safepal Discloses New Customer Data Incident: Almost 40K Users Involved
Safepal, a wallet shaper headquartered successful the Seychelles, is facing a information situation involving a subset of its users.
On Sunday, the institution disclosed that it had suffered an unauthorized information breach involving 39,798 customers aft a plugin utilized for bid tracking suffered a flaw that allowed unidentified actors to entree this information.
The information breach progressive customers’ orders betwixt March 2, 2025, and April 11, 2026, exposing perchance captious information, including names, email addresses, shipping addresses, telephone numbers, and acquisition details, to the attackers.
The institution ensured that effect phrase, backstage keys, wallet password, oregon different wallet credentials were not extracted during this incident.
Safepal acknowledged that the breach mightiness pb to blase phishing attempts, including “fraudulent telephone calls, emails, substance messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, oregon different attempts to get your wallet credentials oregon further idiosyncratic information.”
Even so, Safepal claims it fixed the contented and implemented caller information measures to forestall akin breaches, including tightening the information retention play to 90 days and taking down 30 fraudulent websites linked to scam schemes.
Nonetheless, information researcher Tay stressed that it is improbable this dataset was utilized lone for phishing, arsenic shipping addresses and idiosyncratic information were disclosed, suggesting a higher risk for users whose addresses were breached.
Specter, different blockchain investigator, stressed that the institution had been receiving reports of phishing attempts arsenic aboriginal arsenic April but did not disclose it until now. Tay confirmed that respective cases were reported during outpouring and summertime that mightiness beryllium linked to this leak.
A lawsuit allegedly progressive successful the breach pointed retired that the institution had deleted his information earlier this disclosure, criticizing Safepal’s information retention policies.
Safepal’s announcement follows akin incidents astatine Trezor, with Shipmonk, its shipping provider, suffering a information breach that exposed the afloat names, email addresses, telephone numbers, and shipping addresses of 11,742 customers successful the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The question of breaches is worrying for users involved, arsenic cryptocurrency holders person been targeted successful alleged wrench attacks, peculiarly successful France.

1 day ago









English (US)