SafePal, the Binance-backed maker of hardware and software crypto wallets, has disclosed a data breach affecting roughly 39,798 customers, all of whom placed orders between 2 March 2025 and 11 April 2026.
SafePal breach leaks the addresses but not the crypto, which may be the bigger problem
SafePal, the Binance-backed maker of hardware and software crypto wallets, has disclosed a data breach affecting roughly 39,798 customers, all of whom placed orders between 2 March 2025 and 11 April 2026.
thenextweb.com
Publisher
Aug 17, 2026 at 8:58 AM UTC · 3 phút đọc

The exposed records cover order information, namely names, physical addresses and contact details. It is the kind of leak that feels almost quaint next to the year’s bigger heists, such as when ShinyHunters dumped 45GB of Madison Square Garden data, until you consider who the customers are.
First, the reassuring part. SafePal is adamant that no cryptocurrency funds were touched, and that passwords, private keys, seed phrases, bank details, payment-card numbers and government-issued IDs all stayed out of reach.
Wallet security held, and users’ digital assets were never compromised. For a company whose entire pitch is safekeeping, that distinction matters enormously, and it is the line the firm will be keenest to repeat.
The cause was mundane, as these things usually are. SafePal blames an “authorization flaw” in a third-party plug-in used for order tracking, which let attackers view other customers’ order details simply by manipulating order numbers.
It is a textbook insecure-direct-object-reference bug, the sort of thing that should be caught in a first-year security review, sitting quietly in a bolt-on tool.
Article Intelligence
Topics
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
