Skip to content
SafePal Data Breach Exposes Personal Information of 39,798 Customers

SafePal Data Breach Exposes Personal Information of 39,798 Customers

First seen 16 Aug 2026, 15:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 17, 2026 at 14:52 UTC
  • •39,798 customers' personal data exposed due to an authorization flaw in SafePal's order system.
  • •No sensitive wallet information, such as seed phrases or private keys, was compromised.
  • •SafePal has implemented additional security measures and notified affected customers.

SafePal disclosed a significant data breach on August 16, 2026, affecting approximately 39,798 customers due to an authorization flaw in its order-tracking plugin. The breach exposed personal details such as names, email addresses, shipping addresses, and phone numbers for orders placed between March 2, 2025, and April 11, 2026. However, sensitive information like seed phrases, private keys, and wallet passwords remained secure. The flaw allowed unauthorized access to customer order information, which could be exploited for phishing attacks. SafePal has since patched the vulnerability and implemented additional security measures. Affected customers were notified via email, and SafePal has taken down over 30 fraudulent websites linked to the breach. The company has also introduced a verification tool for customers to check if their data was compromised.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-05-01
Phishing report received
SafePal received a phishing report that was initially treated as an isolated incident.
Finance.Biggo
2026-07-01
Formal security investigation initiated
SafePal escalated its investigation into the order-tracking plugin flaw after discovering the breach.
Finance.Biggo
2026-08-16
Data breach disclosed
SafePal publicly announced the breach affecting 39,798 customers and outlined the exposed data.
thecurrencyanalytics.com
2026-08-16
Security measures implemented
SafePal patched the vulnerability and introduced additional security controls to protect customer data.
Bleepingcomputer
2026-08-16
Affected customers notified
SafePal emailed all affected customers with details on the breach and how to verify their order status.
Safepal

More articles in this cluster (40)

Following this threat?

Track Coldcard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed