SafePal Data Breach Impacts Nearly 40,000 Customers: A Warning About Customer Data and Third Party Security

A recent data breach involving cryptocurrency hardware wallet provider SafePal highlights an important cybersecurity lesson: even when highly sensitive credentials remain protected, customer information stored within supporting systems can still become a valuable target for attackers.

According to a recent SecurityWeek report, SafePal is notifying approximately 40,000 individuals after attackers exploited a vulnerability in an order tracking function associated with a customer order information plugin. The incident affected information connected to customers who placed orders between March 2, 2025 and April 11, 2026.

The reported exposure included customer names, physical addresses, email addresses, phone numbers, and order information. SafePal stated that seed phrases, private keys, wallet passwords, payment card information, bank account information, and government identification numbers were not involved in the breach.

While the most sensitive wallet credentials were reportedly not exposed, the incident demonstrates how seemingly routine customer information can become extremely valuable when combined with social engineering and targeted phishing campaigns.

How the Attack Happened

The reported incident involved a vulnerability in an order tracking component used to process customer order information.

Attackers were able to exploit the weakness and gain access to customer-related data.

This illustrates a broader security challenge faced by organizations today. Applications rarely operate in isolation. They depend on plugins, APIs, cloud services, payment systems, customer management platforms, logistics providers, and other third party technologies.

A vulnerability in one supporting component can therefore create a path toward sensitive organizational or customer information.

Why Customer Information Matters

Names, email addresses, phone numbers, and physical addresses may appear less sensitive than passwords or financial credentials, but attackers can use this information to build convincing targeted attacks.

For cryptocurrency users in particular, exposed customer information could potentially be used to create highly personalized phishing attempts.

Attackers may attempt to impersonate:

• Wallet providers
• Cryptocurrency exchanges
• Shipping companies
• Customer support teams
• Financial institutions
• Security teams
• Cryptocurrency recovery services

A convincing message containing accurate customer information can significantly increase the likelihood that a victim will trust the communication.

The Phishing Risk After a Data Breach

SafePal has warned affected customers to remain cautious about suspicious communications requesting sensitive wallet information.

This is an important distinction.

A breach does not necessarily need to expose a private key or seed phrase to create a serious security risk.

Attackers can use legitimate customer information as the foundation for a second stage attack.

For example, a threat actor who knows a customer’s name, phone number, address, and recent purchase information may be able to construct a highly convincing social engineering campaign.

The objective could then be to trick the victim into voluntarily providing credentials or recovery information.

Data Retention Can Increase Cybersecurity Risk

Another important lesson from the incident involves data retention.

SafePal reported that its investigation identified an issue that resulted in order-related information being retained for longer than intended. The company subsequently reviewed and rebuilt its order processing pipeline and tightened the applicable retention period.

This reinforces a fundamental security principle:

Organizations cannot protect information effectively if they do not know what information they have, where it is stored, who can access it, and how long it should be retained.

Reducing unnecessary data retention can reduce the potential impact of future breaches.

Third Party Components Need Continuous Security Testing

Organizations frequently depend on external plugins and software components to provide essential functionality.

However, every additional component introduces another potential attack surface.

Security programs should therefore include:

• Third party application assessments
• Plugin and dependency vulnerability management
• Secure configuration reviews
• API security testing
• Application penetration testing
• Software composition analysis
• Access control reviews
• Data flow mapping
• Data retention assessments
• Continuous vulnerability monitoring

Security testing should not stop after deployment. Applications and their dependencies change continuously, which means security validation also needs to be continuous.

Cryptocurrency Companies Face Unique Security Challenges

Cryptocurrency businesses manage a combination of digital assets, customer identities, financial information, transaction data, and highly targeted users.

This makes them attractive targets for cybercriminals.

Organizations operating in the cryptocurrency and financial technology ecosystem should consider implementing layered controls covering:

• Customer data protection
• Identity and access management
• Phishing and social engineering defenses
• API security
• Application security
• Cloud security
• Secure software development
• Data loss prevention
• Threat detection and monitoring
• Incident response
• Security awareness training

Protecting customer information is not simply a privacy requirement. It can also be an important defense against account takeover, fraud, impersonation, and targeted phishing.

Industries That Can Learn From This Incident

The lessons from this incident extend well beyond cryptocurrency companies.

Financial Services and FinTech

Banks, payment providers, digital wallets, and financial technology companies manage large amounts of sensitive customer information.

COE Security can help these organizations assess applications, APIs, cloud environments, identity controls, and customer data protection mechanisms.

Retail and E-Commerce

Retail organizations often store customer names, addresses, phone numbers, purchase histories, and shipping information.

COE Security can help retailers identify vulnerabilities across customer-facing applications, APIs, cloud infrastructure, and third party integrations.

Healthcare

Healthcare organizations manage highly sensitive patient and customer information across numerous interconnected systems.

Security assessments, data protection programs, vulnerability management, and compliance-focused security controls can help reduce exposure.

Manufacturing and Technology

Manufacturers and technology companies increasingly depend on connected applications, cloud services, APIs, and third party software.

COE Security can help identify weaknesses across application, network, cloud, IoT, and software development environments.

Government

Government organizations manage large amounts of personal and operational information.

Security testing, data governance, vulnerability management, monitoring, and compliance programs can help strengthen protection against unauthorized access and data exposure.

Key Cybersecurity Takeaways

The SafePal incident provides several lessons that organizations can apply immediately:

1. Protect all customer data

Security programs should consider names, addresses, phone numbers, and order histories as potentially valuable information.

2. Review third party components

Plugins, APIs, SaaS platforms, and external services should be continuously assessed for vulnerabilities.

3. Minimize data retention

Organizations should retain information only for as long as there is a legitimate business, legal, or regulatory requirement.

4. Monitor for secondary attacks

After a breach, organizations should expect increased phishing, impersonation, and social engineering attempts.

5. Strengthen customer communication

Customers should receive clear security guidance following an incident, particularly when attackers may attempt to exploit leaked information.

6. Test applications continuously

Penetration testing and vulnerability assessments should be integrated into the software lifecycle rather than performed only once.

Conclusion

The SafePal data breach is a reminder that cybersecurity risks can exist in unexpected parts of an organization’s technology environment.

A vulnerability in an order tracking component may not directly expose cryptocurrency wallet credentials, but compromised customer information can still create opportunities for phishing, impersonation, fraud, and social engineering.

The incident also highlights the importance of data minimization, secure third party integrations, continuous vulnerability management, application security testing, and strong incident response processes.

As organizations continue expanding their digital ecosystems, cybersecurity must cover the entire data lifecycle, from collection and processing to storage, access, retention, and eventual deletion.

Protecting sensitive credentials is essential, but protecting the information that attackers can use to target the people behind those credentials is equally important.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services

In addition, COE Security helps organizations strengthen protection against data breaches and third party cyber risks through application security assessments, API security testing, cloud security assessments, vulnerability management, penetration testing, secure software development practices, data governance, third party risk assessments, phishing risk assessments, identity and access management reviews, incident response planning, and continuous security monitoring.

For financial services, FinTech, cryptocurrency, and digital payment organizations, we help protect customer information, applications, APIs, digital assets, identity systems, and cloud environments.

For retail and e-commerce organizations, we help secure customer data, online applications, payment environments, APIs, and third party integrations.

For healthcare organizations, we help protect sensitive information while supporting security and compliance requirements.

For manufacturing and technology organizations, we help assess application, cloud, IoT, network, and software supply chain security risks.

For government organizations, we help strengthen data protection, application security, vulnerability management, monitoring, and compliance readiness.

Our goal is to help organizations identify vulnerabilities before attackers can exploit them, strengthen cyber resilience, protect sensitive information, and maintain compliance with evolving security requirements.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article