SafePal Data Breach Exposes Personal Information of 39,798 Customers

A security incident at SafePal, a non‑custodial wallet provider backed by Binance and Animoca Brands, was announced on 16 August 2026. The breach resulted from an authorization flaw in an order‑tracking plugin, allowing attackers to access names, email addresses, phone numbers, shipping addresses and purchase details for 39,798 customers who placed orders between 2 March 2025 and 11 April 2026. The exposed data does not include seed phrases, private keys, wallet passwords, bank details, payment card numbers or government identification documents, and SafePal has stated that no wallet access or funds were compromised.

Details of the Breach

  • Affected Data: Customer names, emails, phone numbers, shipping addresses and order histories.
  • Scope: 39,798 customer records, spanning an 13‑month period.
  • Technical Cause: An authorization flaw in an order‑tracking plugin that permitted cross‑access between user records.
  • Security Measures Taken: SafePal patched the plugin, reduced order‑data retention to 90 days, notified all affected users by email and provided a dedicated web page for customers to verify exposure.

Implications for Users

The combination of personal identifiers and evidence of cryptocurrency ownership can potentially target high‑net‑worth holders for physical attacks. While wallet credentials remained secure, the personal data exposed could be used by criminals to locate and target individuals.

Market Response

SafePal’s market capitalization is currently $115 304 495.98. The coin, which traded at $0.230609 on 15 August 2026, has experienced a 52‑week high of $0.607019 on 23 September 2025 and a 52‑week low of $0.199892 on 28 July 2026. Following the breach announcement, the token’s price reflected a modest decline, indicating that investors are monitoring the incident closely but are not yet taking extreme action.

Context within the Hardware‑Wallet Sector

The breach adds to a recent pattern of security incidents affecting hardware wallet providers. Earlier this week, Trezor disclosed a leak that exposed 13,689 customer records. Combined, the two incidents have placed 53,487 customer records in the public domain, though neither company reported a loss of funds.

SafePal’s Position

SafePal emphasizes that seed phrases, private keys, bank details, and card numbers were not accessed. The company asserts that the wallet itself remained secure and that the incident involved only the commerce side of its operations. SafePal has implemented additional security measures to prevent similar incidents in the future.


The article is based solely on information provided in the input sources and the fundamental data for SafePal.