Monday, 17 August 2026Sports · Finance · Markets · Analysis

NEWSORACLE

Homefinance
financeCrypto

SafePal Crypto Wallet Breaches 39,798 Customer Records

By NewsOracle Editorial16 August 202620:00 GMT2 min read
Based on reporting from CoinDesk
SafePal Crypto Wallet Breaches 39,798 Customer Records

Key Points

  • SafePal disclosed on Sunday that an authorization flaw in its order-tracking plug-in exposed personal data of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • The breach compromised names, physical addresses, and contact details, but SafePal confirmed that private keys, seed phrases, cryptocurrency funds, passwords, and government IDs were not affected.
  • The company patched the vulnerability, hired an independent third-party security firm to audit the fix, and identified and removed more than 30 fraudulent websites and phishing links associated with the breach.

SafePal implemented a 90-day data retention policy for personal information in its order-processing system, down from an unspecified previous duration. The company cautioned that users who shared their private keys or seed phrases via phishing emails, phone calls, or letters should treat their wallets as compromised and transfer assets to a new wallet. A verification tool on SafePal's website allows customers to check whether their data was affected.

The SafePal breach follows a recent hack of Coldcard hardware wallets in which attackers reportedly stole at least $120 million in bitcoin. Both incidents underscore that the cryptocurrency hardware wallet sector faces ongoing security challenges despite being positioned as a safer alternative to online exchanges. SafePal's breach differed in scope and severity—targeting customer personal data rather than wallet security itself—yet the pattern of breaches affecting multiple major hardware wallet providers within a short timeframe suggests that attackers are increasingly targeting the peripheral systems that support custody solutions, not just the cryptographic keys themselves. This shift in attack vectors raises questions about whether users should diversify both their holdings and the types of wallets used to store them, as no single solution eliminates risk entirely.

Related Guide: Read our complete guide →

Market Outlook

SafePal's 90-day data retention policy and third-party security audit may become industry standards as regulators scrutinize cryptocurrency custody providers. The company's response—removing 30+ phishing links and patching within days—suggests the breach will not materially impact customer confidence in hardware wallets, though heightened phishing attempts targeting exposed customers are likely through mid-2026.

Sources: CoinDesk and other international news outlets.

Share this article

Disclaimer: This article was produced with AI assistance based on publicly available news sources. While we strive for accuracy, NewsOracle makes no warranty as to the completeness or accuracy of the information. Errors and omissions may occur. Readers should independently verify all information before acting on it. NewsOracle does not intend to defame any individual or organisation and accepts no liability for any loss or damage arising from reliance on this content. Content is for informational purposes only and does not constitute legal, financial, medical, or professional advice. All rights reserved. Unauthorised reproduction prohibited.

N

NewsOracle Editorial

The NewsOracle Markets Desk covers stock markets, cryptocurrency, economic policy and breaking financial news from Wall Street and global exchanges.

Latest coverage: Crypto

More from NewsOracle