SafePal, a crypto wallet provider, said it experienced a data breach that exposed personal order information for nearly 40,000 customers. The company moved quickly to reassure users that the incident did not touch private keys, seed phrases, or crypto assets.
What the breach exposed
The breach affected order details, meaning the kind of information tied to purchases — potentially shipping addresses, contact details, and transaction histories. SafePal did not specify exactly which fields were included, but the scale suggests a meaningful chunk of its user base. The company hasn't said how the intruders got in or when they found the breach.
What wasn't touched
The critical part: private keys, seed phrases, and crypto assets remain safe. That means the breach is an inconvenience and a privacy risk, but not a direct threat to funds. For a crypto company, that distinction matters — wallets live and die on the security of keys, and SafePal says those are untouched.
Unanswered questions
The biggest gap is how the breach happened. SafePal hasn't disclosed the attack vector, whether it involved a third-party vendor, or how long the data was exposed. Also unclear is what the company is doing for affected users. For now, the advice is standard for any data leak: watch for phishing attempts, especially ones that reference your order history. If you're one of the 40,000, changing passwords won't hurt, but the real risk is social engineering.




