The SafePal breach exposes the addresses, but doesn't compromise the cryptocurrency, which could be the more significant issue.
SafePal, the company behind hardware and software crypto wallets backed by Binance, has revealed a data breach that impacts approximately 39,798 customers, all of whom placed orders between March 2, 2025, and April 11, 2026. The compromised records include order information such as names, physical addresses, and contact details. While it might seem less significant compared to larger breaches this year, like ShinyHunters' release of 45GB of data from Madison Square Garden, the identity of the affected customers adds a layer of concern.
On a positive note, SafePal reassures that no cryptocurrency funds were accessed, and that passwords, private keys, seed phrases, bank details, payment card numbers, and government-issued IDs remained secure. The integrity of wallet security has been upheld, and users’ digital assets were never compromised. For a company focused on safekeeping, this distinction is crucial, and it’s a message SafePal will likely emphasize.
The cause of the breach was relatively mundane. SafePal attributes it to an “authorization flaw” in a third-party plug-in used for order tracking, which allowed attackers to view details of other customers' orders simply by altering order numbers. This is a classic case of an insecure direct object reference bug, something that should have been caught during a basic security review, hidden within an auxiliary tool.
SafePal claims it promptly patched the vulnerability and has since reached out to affected users from the email address [email protected]. Additionally, they have hired an independent third-party auditor, reduced their data retention period to 90 days, identified and removed over 30 fraudulent websites and phishing links, and provided customers with a tool to verify if their information was involved in the breach.
In terms of breach responses, this is a well-organized approach and significantly quicker than the typical corporate responses associated with such disclosures. However, here's the uncomfortable reality: this crypto breach did not compromise cryptocurrency but leaked personal addresses, which may prove to be a more perilous loss for this customer demographic. While strangers cannot empty a wallet with just a postal address, they can do a great deal more with that information.
The immediate concern is familiar. With access to names and contact details of nearly 40,000 identified crypto owners, malicious actors have an ideal target list for phishing and impersonation attacks, especially as the emails will appear credible due to the sender's knowledge of individual purchases and delivery details. This aligns with the same social-engineering tactics that support operations like those behind Ryuk ransomware, which has generated $3.7M in Bitcoin for its creators.
The less obvious risk is physical, and it is more serious. For individuals known to possess cryptocurrency, a leaked name linked to a home address raises the possibility of a “wrench attack,” a term describing coercing someone to relinquish their keys in person. Given that crypto transactions are irreversible and difficult to trace, the temptation to show up at the victim’s doorstep is substantial. Reports of crypto holders being targeted, robbed, and worse have been increasing, making the exposure of a comprehensive list of verified owners with addresses particularly detrimental.
Another predictable takeaway is that the weak point was not SafePal’s own system, but rather a third-party plug-in integrated into it, a trend that has become more prevalent in recent data breaches. This mirrors recent incidents, such as the one that affected cosmetics giant Estée Lauder through an Oracle E-Business flaw: the core system remained secure, while the ancillary tool did not.
SafePal deserves recognition for its quick and unusually transparent response, as well as for maintaining a product where a breach of the storefront did not impact the wallets themselves. However, this incident serves as a reminder that in the crypto landscape, privacy is not a minor feature added alongside security. For a customer whose name and address are now publicly available, there is no way to patch or change where they live, making the issue of privacy a critical aspect of security.
Other articles
The SafePal breach exposes the addresses, but doesn't compromise the cryptocurrency, which could be the more significant issue.
SafePal, the cryptocurrency wallet creator backed by Binance, has revealed a security breach that has compromised the names and physical addresses of almost 40,000 customers, increasing the risks of phishing and physical attacks.
