SafePal Breach Leaks Customer Addresses but Not Crypto
A Binance-backed wallet maker kept its customers’ funds and keys safe, then handed attackers the one thing a crypto holder least wants leaked: where they live.
August 17, 2026 – 8:57 am
Credit: SafePal
SafePal, the Binance-backed maker of hardware and software crypto wallets, has disclosed a data breach affecting roughly 39,798 customers, all of whom placed orders between March 2, 2025, and April 11, 2026. The exposed records include order information:
- Names
- Physical addresses
- Contact details
While no cryptocurrency funds were compromised, this leak poses a significant risk to customers due to the sensitive nature of their personal information.
First, some good news:
- Wallet security held: SafePal asserts that passwords, private keys, seed phrases, bank details, payment card numbers, and government-issued IDs remained secure.
The breach was caused by a third-party plug-in used for order tracking, suffering from an "authorization flaw" that allowed attackers to view other customers’ order details through manipulation of order numbers. This is a common type of vulnerability known as an insecure direct object reference (IDOR) bug, which should have been caught during security reviews.
SafePal has taken several steps in response:
- Immediately patched the flaw.
- Emailed affected users from [email protected].
- Hired an independent third-party auditor.
- Reduced data retention periods to 90 days.
- Identified and removed fraudulent websites and phishing links.
- Provided customers with a tool to check if their information was compromised.
The concern here is twofold:
-
Targeted Phishing: Attackers now possess names and contact details for nearly 40,000 crypto owners, making them prime targets for targeted phishing and impersonation attacks.
-
Physical Danger: Leaked addresses expose customers to the risk of "wrench attacks," where attackers physically coerce individuals into revealing their private keys.
The weak link in this scenario was not SafePal’s vault but a third-party plug-in bolted onto its system.