DEV Community

Cover image for SafePal Data Breach: Exposes Nearly 40,000 Customers Personal Information
EzSecure
EzSecure

Posted on

SafePal Data Breach: Exposes Nearly 40,000 Customers Personal Information

The first thing people usually think about when they hear about a crypto wallet data breach is stolen cryptocurrency, private keys, or wallet credentials.

The recent SafePal case presents a different picture.

Additionally, the company was hit by a data breach on August 16, 2026, compromising customer order data. The incident has reportedly affected 39,798 customers and exposed personal and purchase information.

SafePal said the incident did not affect customers’ private keys, seed phrases, wallet passwords, payment card information, bank details or government IDs. There was also no evidence that customer funds were accessed.

So why is this matter important?

It shows that the most sensitive data of a company is not always stored where you expect it to be.

What Happened in the SafePal Data Breach?

SafePal detected unauthorised access of customers’ order information through a vulnerability in an order tracking plugin.

The bug reportedly enabled unauthorised access to order information of other customers in some conditions. SafePal has investigated the incident and resolved the issue, and has implemented further measures to mitigate the issue.

Customers who ordered during the relevant time period were affected by the incident.

The information reportedly included details like:

  • Call names
  • Email addresses
  • Phone numbers
  • Delivery Addresses
  • Order info
  • Details of Order

Although these details might not seem as sensitive as the private key of a cryptocurrency wallet, together they can give useful information about a person.

The Crypto Wallet Wasn’t the Main Problem

The interesting thing about the SafePal case is that no one accessed customers’ cryptocurrency wallets during the incident.

What was leaked instead was information about customer orders.

And this points to a very real fact of modern businesses.

A company may have rigid controls around its mainline product, but customer information may be flowing through other systems.

For example, in an e-commerce transaction information may flow through:

Website > Ordering System > Database > Plugin > Shipping > Customer Support

Every stage can generate or hold information.

The most readily available customer data may not be in the core product.

Why Customer Order Data Matters

Information like a name, phone number, address, or purchase history is easy to underestimate.

But put together, these details can paint a much more complete picture of a customer.

For example, revealing a shipping address provides a real-world location.

A phishing email address can be aimed at.

A phone number can be used to perform social engineering.

Purchase data can reveal what someone bought and when they bought it.

For a crypto wallet company, learning that someone bought a hardware wallet might make them more vulnerable to scams that impersonate customer support.

So customer information can be very valuable even if wallet credentials and funds are untouched.

Third-Party Tools Can Become Part of Your Data Environment

The SafePal case also indicates the need to look beyond an organization’s primary systems.

Modern businesses depend on plugins, APIs, SaaS platforms, integrations, analytics programs, shipping systems and other third-party technologies.

These tools often make business operations easier, but they can also be part of the path taken by customer information.

That means that organisations need to understand not only what tools they are using, but also:

  • What data does each system work on
  • Where that information’s kept
  • Type of information involved
  • How long the information stays there
  • What systems can get there

Without the visibility enabled by this process, businesses often have an incomplete picture of their actual data environment.

Data Retention Is Another Important Lesson

In addition to data retention, SafePal data breach also highlights another issue related to the storage of customer records.

According to media reports, SafePal discovered a configuration fault that was allowing them to keep older-order records longer than the expected retention time. The business has then decided to limit the duration their order-data was retained in their system to 90 days.

One of the most significant questions the SafePal incident brings to our attention, besides data safety, is as follows:

What is the volume of old customer data currently at our disposal?

Keeping data doesn’t necessarily equate to being wrong. Some information must remain with you due to business, legal, regulatory, or other contractual reasons. So keeping data for those purposes is fine. The main problem comes when a business lacks these knowledge and abilities:

First, what are the pieces of information kept?

Second, the purpose of the information that is kept?

Third, what is the location where the information is stored?

Fourth, the period during which the information needs to be retained?

A thorough review at least once every while of information that has been archived can assist businesses in their decision making about what to retain.

What Businesses Can Learn From the SafePal Data Breach

The events of SafePal serve as an example providing not only crypto enthusiasts but also others with valuable lessons.

Search for Sensitive Information Outside Core Systems
Secret data can hide not only in core applications but in many other places. Order systems, plugins, shared files, databases, and customer support platforms can all include customer data.

Improve the Visibility of Your Data
Organizations should be capable of figuring out where their most sensitive information resides in the company’s ecosystem. It is one thing to know that a company is using ten softwares, and totally another thing if, say, one of them contains the customer’s personal details.

Clarify Your Knowledge of Available Information
Not every type of information is equally sensitive.

Classifying and labeling data can be really helpful. It can show a company what type of personal details it handles customer records, financial data, company employees’ information or any other kind of confidential data.

Regularly Reassess the Storage of Data
Information that is obsolete is not supposed to be kept just in case.

Companies shouldn’t overlook the question of keeping records. They need to constantly check if their need for data is still relevant and if the keeping of it complies with their business requirements.

Be Aware of Your Ecosystem
Plug-ins, third-party platforms and system integrations might all get connected to a company’s data flow.

Mapping how information passes through those systems is a crucial step to being in control of data visibility.

The Bigger Lesson From SafePal

The SafePal breach was not about a cryptocurrency theft.

According to the SafePal announcement, private keys, mnemonic seed phrases, wallets’ passwords, payment details, and government IDs were not accessed, and customer assets were never reported missing.

Still, nearly 40, 000 customers’ personal and order-related information had been exposed.

This is a key difference.

A company generally puts effort and resources towards protecting the assets that they think are their most valuable. However, information about these assets may be as crucial from the privacy and regulation aspect as the assets themselves.

Customer order may look like an ordinary business file.

However, it can also show the customer’s name, postal address, telephone number, and shopping history.

In addition, a failure by the company to track where such information is stored makes the management of it quite difficult.

Probably the most significant takeaway from the SafePal incident is simply this:

Ask not only what data your business is shielding. Inquire also what kinds of data you own, where you keep them safe, and for how long.

Certainly, in some cases, the primary data-problem may not be the data directly related to the business but a data by-product of the business.

Read the official SafePal security update here:

Unauthorized Access to a Subset of Customer Order Information — SafePal

Top comments (0)