SafePal data breach impacts 39,798 customers, stolen info for sale
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
Source: BleepingComputer · August 17, 2026 at 4:31 AM · AI-assisted report

KUALA LUMPUR, 17 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
SafePal Data Breach Exposes 39,798 Malaysian Customers to Phishing Risks
Market Impact
KUALA LUMPUR, Aug 17 — Cryptocurrency hardware wallet provider SafePal has disclosed a data breach affecting 39,798 customers globally, including Malaysians, after a security flaw allowed unauthorized access to order details. A threat actor is now claiming to sell the stolen data on a cybercrime forum, raising concerns over potential phishing attacks targeting affected users.
The breach, which SafePal says was discovered in July, impacts customers who placed orders between March 2, 2025, and April 11, 2026. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase information. Crucially, the company confirmed that wallet seed phrases, private keys, passwords, and financial details were not compromised.
SafePal notified all affected customers via email on August 16, with the subject line "[Important] Your SafePal Order Information Has Been Affected." The company has also launched an online verification tool where users can check if their order details were exposed by entering their order number and shipping country.
A threat actor, spotted by cybersecurity researcher DarkWebInformer, is now selling the stolen data on a dark web forum. The seller claims to have information on approximately 39,798 customers and offers to provide order IDs and shipping countries as proof of authenticity. The post warns potential buyers against lowball offers, stating: "Not interested in low balls, please come correct and with a good price or do not message me at all."
SafePal first received reports of suspicious activity in early May 2026, initially treating them as isolated phishing attempts. However, the company later escalated the issue into a formal security investigation after discovering an authorization flaw in its order-tracking system. The flaw, found in a third-party plug-in, allowed unauthorized access to customer order information.
In July, SafePal initiated a "full review and rebuild" of its order-processing system and identified the vulnerability. The company has since fixed the flaw, implemented additional security measures, and is working with a third-party security firm to validate the fix and conduct a broader review of its systems.
During the investigation, SafePal also uncovered a separate configuration error that caused a data-cleanup process to malfunction between September 2025 and April 2026. This error resulted in the retention of order data dating back to March 2025, further exposing customer information.
To mitigate risks, SafePal has purged personal data from its active e-commerce servers, though it retains an encrypted offline copy for potential law-enforcement investigations. The company has also taken down over 30 fraudulent websites and phishing links tied to the incident.
SafePal has reassured customers that they do not need to replace their hardware wallets or move their cryptocurrency assets due to the breach. However, users who have already shared their seed phrases or private keys in response to phishing attempts are advised to treat their wallets as compromised and transfer their assets to a new wallet on a trusted SafePal device or official application.
The breach highlights the growing threat of targeted phishing attacks, particularly in the cryptocurrency sector, where attackers often exploit stolen personal data to gain access to digital assets. SafePal’s incident underscores the importance of robust security measures and proactive customer communication in mitigating such risks.
Malaysian cybersecurity experts have weighed in on the incident, emphasizing the need for heightened vigilance among cryptocurrency users. "Phishing attacks are becoming increasingly sophisticated, and users must verify the authenticity of any communication claiming to be from their wallet provider," said a spokesperson for CyberSecurity Malaysia, the national cybersecurity agency.
The breach also raises broader concerns about third-party integrations and supply chain security in the cryptocurrency industry. SafePal’s reliance on external logistics partners and plug-ins underscores the vulnerabilities that can arise from interconnected systems.
Industry analysts note that this incident is part of a growing trend of cyberattacks targeting cryptocurrency firms. Earlier this year, medical billing firm MCBS reported a breach affecting 1.26 million people, while cloud communications provider RingCentral disclosed a breach exposing 1.6 million accounts. These incidents highlight the persistent threat of data breaches across multiple sectors.
For affected Malaysian users, SafePal has advised caution when receiving unsolicited emails or calls related to their accounts. The company warns that attackers may use the stolen data to impersonate SafePal staff, offering firmware updates, product returns, refunds, or legal investigations as pretexts for further exploitation.
As the investigation continues, SafePal is urging customers to enable two-factor authentication (2FA) on their accounts and to report any suspicious activity immediately. The company has also pledged to enhance its security protocols and conduct regular audits to prevent future breaches.
Looking ahead, the incident serves as a reminder of the critical importance of cybersecurity in the digital asset space. With cryptocurrency adoption on the rise in Malaysia and across Southeast Asia, firms must prioritize robust security measures to protect user data and maintain trust in the ecosystem.
For now, affected users are advised to remain vigilant, verify any communications claiming to be from SafePal, and take immediate action if they suspect their wallet has been compromised. The breach serves as a stark warning of the evolving tactics used by cybercriminals—and the need for constant vigilance in an increasingly digital world.