EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SafePal discloses security breach, affecting 39,798 users, increasing phishing risk

2026-08-17 12:11:37
Bookmark

SafePal said on Sunday that a security incident resulted in the disclosure of order information for approximately 39,798 customers, all of which were placed between March 2 and April 11 this year.

SafePal pointed out in a blog announcement: "This incident did not involve your mnemonic words, private keys, wallet passwords or other wallet credentials, nor did it involve bank account information, payment card numbers or government-issued identification numbers. SafePal never requests, collects, processes or stores such information from customers."

Under certain conditions, this vulnerability may allow unauthorized personnel to view other customers 'order information. SafePal said the issue has been fixed and the company has added more security controls to the affected systems.

SafePal reminds affected customers that fraudsters may use stolen order details to make phishing attacks appear more credible. The company has sent email notifications to customers whose data may be at risk. Customers can still determine for themselves whether further action is needed and should not rely solely on information in email notifications.

SafePal lists different ways in which fraudsters may exploit leaked information: Victims may receive misleading phone calls disguised as customer service, phishing emails, text messages, written letters, false refund offers, misleading software and firmware update requests, misleading information posing as customer service, or links to seemingly authentic phishing websites.

The company also warned that stolen order records could eventually be posted or disseminated to public online forums. "Please be vigilant about any unexpected contact or hardware delivery that mentions your SafePal purchase history, whether delivered by phone, mail or in person."

According to SafePal, customers do not need to transfer cryptocurrency to other wallets simply because order data is compromised. Assets need to be transferred only if the recovery phrase or private key is leaked in a suspicious website, email, text message, phone call or letter. If wallet credentials are compromised in some way, SafePal recommends treating the wallet as unsafe.

SafePal hired an independent security company and limited the retention period of personal order data to 90 days after fixing the bug. SafePal said the access control vulnerability has been fixed and additional security measures have been added to the order-related system. The company also hired an independent cybersecurity company to confirm that the fixes worked as expected. Not only will the outside company examine the original issue, it will also conduct a broader security review of SafePal's order processing system to identify other potential vulnerabilities.

SafePal also shortens the time customers 'personal information is retained in relevant order processing systems. The new retention period is 90 days, unless applicable law requires certain information to be retained for a longer period of time.

According to SafePal, they have confirmed which customers 'data was accessed and communicated directly with those customers to provide more details.

In addition, other companies that worked with SafePal to process order shipment and delivery were also involved in the investigation. SafePal requires these external partners to check their own systems for this security vulnerability, not just to SafePal's order environment.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP