{"id":76892,"date":"2026-08-17T01:52:40","date_gmt":"2026-08-17T01:52:40","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/data-breach-hits-39798-safepal-customers-after-order-plugin-flaw\/"},"modified":"2026-08-17T01:52:40","modified_gmt":"2026-08-17T01:52:40","slug":"data-breach-hits-39798-safepal-customers-after-order-plugin-flaw","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/data-breach-hits-39798-safepal-customers-after-order-plugin-flaw\/","title":{"rendered":"Data Breach Hits 39,798 Safepal Customers After Order Plugin Flaw"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Safepal suffered a data breach exposing the personal details and shipping addresses of 39,798 users.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">While wallet keys remain safe, the leaked addresses leave users vulnerable to physical wrench attacks.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Safepal secured the flaw but faces harsh criticism for delaying disclosure despite prior scam reports.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>Safepal Discloses New Customer Data Incident: Almost 40K Users Involved<\/h2>\n<p>Safepal, a wallet manufacturer headquartered in the Seychelles, is facing a security crisis involving a subset of its users.<\/p>\n<p>On Sunday, the company <a href=\"https:\/\/www.safepal.com\/en\/blog\/security-update\" target=\"_blank\" rel=\"noopener noreferrer\">disclosed that it had suffered an unauthorized data breach<\/a> involving 39,798 customers after a plugin used for order tracking suffered a flaw that allowed unidentified actors to access this information.<\/p>\n<p>The data breach involved customers\u2019 orders between March 2, 2025, and April 11, 2026, exposing potentially critical information, including names, email addresses, shipping addresses, phone numbers, and purchase details, to the attackers.<\/p>\n<p>The company ensured that seed phrase, private keys, wallet password, or other wallet credentials were not extracted during this incident.<\/p>\n<p>Safepal acknowledged that the breach might lead to sophisticated phishing attempts, including <strong>\u201cfraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information.\u201d<\/strong><\/p>\n<p>Even so, Safepal claims it fixed the issue and implemented new security measures to prevent similar breaches, including tightening the data retention period to 90 days and taking down 30 fraudulent websites linked to scam schemes.<\/p>\n<p>Nonetheless, security researcher Tay stressed that it is unlikely this dataset was used only for phishing, as shipping addresses and personal data were disclosed, <a href=\"https:\/\/x.com\/tayvano_\/status\/2089012554031087959?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">suggesting a higher risk<\/a> for users whose addresses were breached.<\/p>\n<p>Specter, another blockchain investigator, stressed that the company had been receiving reports of phishing attempts as early as April but did not disclose it until now. Tay confirmed that several cases were reported during spring and summer that might be linked to this leak.<\/p>\n<p>A customer allegedly involved in the breach pointed out that the company had deleted his data before this disclosure, criticizing Safepal\u2019s data retention policies.<\/p>\n<p>Safepal\u2019s announcement follows similar incidents at Trezor, with Shipmonk, its shipping provider, <a href=\"https:\/\/news.bitcoin.com\/security\/trezor-shipping-provider-exposes-13689-crypto-customers-to-scams\/\">suffering a data breach that exposed<\/a> the full names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.<\/p>\n<p>The wave of breaches is worrying for users involved, as <a href=\"https:\/\/news.bitcoin.com\/france-charges-88-crypto-kidnappings-2026\/\">cryptocurrency holders have been targeted<\/a> in so-called wrench attacks, particularly in France.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/data-breach-hits-39798-safepal-customers-after-order-plugin-flaw\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Safepal suffered a data breach exposing the personal details and shipping addresses of 39,798 users. While wallet keys remain safe, the leaked addresses leave users vulnerable to physical wrench attacks. Safepal secured the flaw but faces harsh criticism for delaying disclosure despite prior scam reports. Safepal [&hellip;]<\/p>\n","protected":false},"author":15,"featured_media":76893,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76892"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=76892"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76892\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/76893"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=76892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=76892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=76892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}