Wallet provider SafePal says data breach exposed personal info of nearly 40,000 customers | The Block

August 16, 2026 2 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: theblock.co

Threat Risk: Medium
Victim: Crypto wallet users
Incident: An authorization flaw in an order-tracking plugin led to a data breach.
Impact: Personal identifiable information of approximately 39,798 customers was exposed.
Attacker: Unidentified threat actors
Analysis: The breach originated from an authorization flaw in a third-party order-tracking plugin, exposing PII for nearly 40,000 customers. Although private keys and seed phrases were not compromised, the leaked data enables highly targeted social engineering attacks. There was a notable delay between early customer reports of phishing and the company’s official confirmation of the root cause.
Recommendations: Ignore unsolicited communications from ‘SafePal support’ requesting wallet credentials or firmware updates; Avoid visiting unofficial support domains such as safepal.support; Implement hardware-based MFA on all sensitive accounts to mitigate the risk of identity theft
Source: The Block

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-17 17:06 UTC

An authorization flaw in an order-tracking plugin led to the exposure of personal data for nearly 40,000 customers. Leak of PII increasing the risk of targeted phishing and social engineering attacks. An authorization vulnerability in a tracking plugin allowed unauthorized users to access order details by manipulating order numbers. This leak exposed a significant amount of PII, including shipping addresses and phone numbers. The primary risk now shifts from direct theft to sophisticated impersonation scams targeting wallet users.

Corroborating source: en.cryptonomist.ch

Leave a Reply

Your email address will not be published. Required fields are marked *