SafePal, the crypto hardware and software wallet provider, has disclosed a data breach that exposed the personal order information of nearly 40,000 of its customers, though the company stressed that no funds or sensitive wallet credentials were compromised.
What Was Exposed
The breach affected order-related data belonging to roughly 40,000 SafePal users. According to the company, the leaked information consisted of personal order details rather than any material tied directly to customers' crypto holdings.
Crucially, SafePal emphasized that private keys, seed phrases, and digital assets remained fully protected throughout the incident. Because those elements are stored on users' devices and never transmitted to the company's servers in a way that would be captured in order records, the exposed data does not give attackers a direct path to drain wallets.
No private keys, no seed phrases, and no crypto assets were touched — only order information was exposed.
Still, order data can carry personal information such as names, contact details, and shipping addresses in the case of hardware wallet purchases. That type of exposure can leave affected users vulnerable to targeted phishing attempts and social engineering schemes.
Why It Matters for Users
Even when funds are safe, data breaches in the crypto sector carry heightened risk because attackers often use leaked personal details to craft convincing scams aimed at tricking victims into surrendering their wallet credentials voluntarily.
Security experts routinely warn that customers whose information appears in a breach should treat any unsolicited messages with suspicion, particularly those claiming to come from the affected company.
- Be wary of unexpected emails or messages referencing recent orders.
- Never share seed phrases or private keys with anyone, regardless of who they claim to be.
- Enable additional account protections where available.
SafePal's disclosure adds to a growing list of breaches that have hit crypto-adjacent service providers, underscoring the ongoing importance of vigilance for users who trust these platforms with their personal information.
