Kucoin SafePal Data Breach Exposes Personal Information of 39,798 Customers
Article Content
- •39,798 customers' personal data exposed due to an authorization flaw in SafePal's order system.
- •No sensitive wallet information, such as seed phrases or private keys, was compromised.
- •SafePal has implemented additional security measures and notified affected customers.
SafePal disclosed a significant data breach on August 16, 2026, affecting approximately 39,798 customers due to an authorization flaw in its order-tracking plugin. The breach exposed personal details such as names, email addresses, shipping addresses, and phone numbers for orders placed between March 2, 2025, and April 11, 2026. However, sensitive information like seed phrases, private keys, and wallet passwords remained secure. The flaw allowed unauthorized access to customer order information, which could be exploited for phishing attacks. SafePal has since patched the vulnerability and implemented additional security measures. Affected customers were notified via email, and SafePal has taken down over 30 fraudulent websites linked to the breach. The company has also introduced a verification tool for customers to check if their data was compromised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (40)
Following this threat?
Track Coldcard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…