Ethical Hacking News
SafePal, a Singapore-based cryptocurrency security company, has disclosed a significant data breach that has exposed the personal information of approximately 39,798 customers. The breach, which occurred between March 2, 2025, and April 11, 2026, was caused by a vulnerability in the company's order-tracking plugin. SafePal has taken measures to prevent similar incidents, including fixing the vulnerability and adding further security measures. Customers are advised to check their status and contact SafePal if they suffered financial losses linked to the breach.
SafePal, a Singapore-based cryptocurrency security company, disclosed a significant data breach exposing approximately 39,798 customers' personal information. The breach, caused by a vulnerability in an order-tracking plugin, exposed names, addresses, email addresses, phone numbers, and order details. Seed phrases, private keys, and wallet passwords were not exposed, but customers who shared these with an attacker should consider their wallet compromised. SafePal took measures to prevent similar incidents, including fixing the vulnerability and reducing data retention to 90 days. The company is working to identify and recover stolen on-chain assets, and urges customers who suffered financial losses to contact them.
SafePal, a Singapore-based company specializing in cryptocurrency security, has disclosed a significant data breach that has exposed the personal information of approximately 39,798 customers. The breach, which occurred between March 2, 2025, and April 11, 2026, was caused by a vulnerability in the company's order-tracking plugin.
According to SafePal, the vulnerability allowed unauthorized access to another customer's order information, resulting in the exposure of names, addresses, email addresses, phone numbers, and order details. The company has confirmed that all affected customers were notified individually by email on August 16 and have urged them to check their status.
SafePal emphasized that seed phrases, private keys, and wallet passwords were not exposed, and therefore, customers do not need to move their assets solely because of the breach. However, anyone who has shared a seed phrase or private key with an attacker should consider the wallet compromised and create a new one using a trusted device or official app, and immediately transfer the remaining funds.
The company pointed out that it does not collect or store bank details, payment card numbers, or government IDs, and there is no evidence that the incident compromised access to customer wallets or funds. Nevertheless, SafePal has taken measures to prevent similar incidents, including fixing the vulnerability, adding further security measures, and reducing data retention to 90 days.
In addition to the measures taken by SafePal, the company has also identified more than 30 fraudulent websites and phishing links and removed them. It will continue monitoring scams, investigating potential risks, and sharing updates through its official channels.
SafePal is urging customers who suffered financial losses linked to the breach to contact the company, which is working with specialists to trace stolen on-chain assets.
This data breach highlights the importance of maintaining robust security measures and being vigilant in protecting sensitive information. As the cryptocurrency space continues to evolve, it is essential for companies like SafePal to prioritize security and transparency to ensure the trust and confidence of their customers.
Related Information:
https://www.ethicalhackingnews.com/articles/SafePal-Data-Breach-Exposes-Personal-Information-of-39798-Customers-ehn.shtml
https://securityaffairs.com/197391/data-breach/safepal-says-39798-customers-hit-by-data-breach.html
Published: Mon Aug 17 14:23:20 2026 by llama3.2 3B Q4_K_M