SafePal (SFP) Data Breach Exposes 39,798 Customer Records

SFP

SFP/USDT

$0.2339
+0.17%
24h Volume

$1,243,938.39

24h H/L

$0.2441 / $0.2305

Change: $0.0136 (5.90%)

Funding Rate

+0.0094%

Longs pay

Data provided by COINOTAG DATALive data
SFP
SFP
Daily

$0.2339

1.39%

Volume (24h): -

Resistance Levels
Resistance 3$0.2658
Resistance 2$0.2497
Resistance 1$0.2352
Price$0.2339
Support 1$0.2288
Support 2$0.2160
Support 3$0.2077
Pivot (PP):$0.235233
Trend:Uptrend
RSI (14):55.6
(07:04 PM UTC)
4 min read
AI SummaryAI
  • SafePal disclosed a data breach affecting 39,798 customers through an authorization flaw in its order-tracking plugin.
  • The affected orders were placed between March 2, 2025 and April 11, 2026.
  • SafePal said seed phrases, private keys, wallet passwords and bank or payment card data were not exposed.
  • More than 30 fraudulent websites and phishing links were removed in response to the leak.

SFP News

SafePal, the Binance-backed hardware wallet provider behind the SFP altcoin, confirmed on August 16 that an authorization flaw in its order-tracking plugin allowed unauthorized access to customer records. The official security disclosure puts the number of affected users at 39,798, spanning orders placed between March 2, 2025 and April 11, 2026. The exposed fields include full names, email addresses, shipping addresses, phone numbers and purchase details. SafePal stated that seed phrases, private keys, wallet passwords, bank account numbers and payment card data were not part of the breach, and that no evidence shows anyone obtained access to wallets or funds. The company said it first received reports of suspicious emails in early May but initially treated them as isolated cases before opening a fuller investigation in July. Despite that, the stolen list has already surfaced for sale on a dark-web cybercrime forum, with the seller sharing sample order IDs and shipping countries to prove authenticity. Security researchers noted that combining home addresses with proof of hardware-wallet ownership creates a high-value target list. SafePal began emailing affected customers on August 16 and said it had taken down more than 30 fraudulent websites and phishing links tied to the leak.

The breach also reopens a broader security debate. A hardware wallet can keep a private key offline, but attacks are increasingly migrating to the human and operational layers around the device. The exploitation of an external order-tracking plugin shows that even users who avoid blind signing and practice good key hygiene can be exposed through vendor-side data handling. The incident landed three days after Trezor said its logistics partner ShipMonk was compromised, and the sequence has put the hardware-wallet sector on notice. The repeated incidents suggest that attackers are focusing on order databases rather than attempting to defeat the devices' encryption directly. With names, addresses and phone numbers matched to evidence of cryptocurrency ownership, the leaked database is a prime tool for targeted phishing, fake support calls and, in extreme cases, physical robbery. SafePal said it removed more than 30 malicious sites and phishing links, and advised customers to treat unsolicited contact with suspicion. Some security experts now advise using a separate address for hardware-wallet deliveries and keeping recovery phrases in multiple locations to reduce physical risk. For end users, the practical takeaway is that delivery addresses and order histories have become part of the security perimeter.

In its official update, SafePal said the vulnerable condition persisted for roughly 13 months — from March 2, 2025 until the flaw was found and corrected — and that the external plugin's tracking feature could make another user's order information visible under certain conditions. The company said the flaw sat in an external order-management plugin rather than in the wallet firmware or its cryptographic key storage, and that the notification to affected customers was sent individually from security@safepal.com with the subject “[Important] Your SafePal Order Information Has Been Affected.” Remediation steps disclosed in the same statement include hiring an independent security firm to validate the fix and review the entire order-processing system, cutting the retention period for personal data in the order environment to 90 days, and confirming with third-party logistics partners that the issue did not propagate further. SafePal also said it removed more than 30 scam sites and phishing links, opened a dedicated support channel for impacted customers, and pointed users to a scam-protection page for reporting new fraudulent links. The disclosure follows a familiar industry pattern; in 2020, Ledger reported that roughly one million customer email addresses were taken, with about 270,000 people also losing names, physical addresses and phone numbers. That track record is why each new wallet-related leak is treated as an urgent threat, even when funds remain untouched.

Across the three updates, the arc is clear: a hardware wallet is only as strong as the web infrastructure and processes around it. SafePal's own security disclosure anchors the analysis — 39,798 customers affected, private keys and funds not exposed, and post-incident controls that include a 90-day retention cap and independent review. In our view, the immediate danger is off-chain targeting rather than on-chain loss: the leaked details can fuel phishing campaigns, including fraudulent airdrop offers, and even physical threats. Users managing positions from hardware wallets to AI Crypto Wallet platforms should treat vendor data practices as part of their risk model and view any unsolicited request for recovery phrases as an attack.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Sarah Chen

Sarah Chen

COINOTAG author

View all posts
AI-AssistedMarket Analyst·Sarah Chen is a market analyst specializing in technical analysis and risk management for cryptocurrency markets, with five years of active trading desk experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments