SecBriefs
← All briefs

SafePal wallets stayed safe—but customer information did not

An order-tracking weakness exposed names and purchase details for 39,798 customers.

Hand-drawn SecBriefs editorial illustration: SafePal wallets stayed safe—but customer information did notSOURCE · Security Affairs
© 2026 SecBriefs · Original illustration
SECBRIEFS ASSESSMENT

SafePal says an order-tracking weakness exposed customer information, including names and purchase details, affecting 39,798 people. Wallets, private keys and seed phrases were not reported as compromised, which is an important distinction: the incident does not mean attackers can automatically move customers’ cryptocurrency. The exposed order context still creates a practical fraud risk. A criminal who knows which device someone bought and when it was delivered can send a support, warranty or security message that feels unusually credible. The likely objective would be to persuade the victim to reveal a seed phrase, approve a transaction or install malicious software. SafePal customers should treat unexpected delivery, refund and wallet-support contacts as untrusted, even when the message contains accurate purchase information. Open the official app or type the company address independently before responding. Never share a recovery phrase with support staff. In this kind of breach, the stolen data is often the opening script for a later attack rather than the final prize.

Read original at Security Affairs

SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.