SafePal disclosed a breach that exposed order and contact details for nearly 40,000 customers, and warned the stolen data may be used to run targeted phishing and impersonation scams. The company cautioned customers to expect fake support messages, refund offers, and firmware-update requests designed to trick people into revealing wallet credentials.
Key findings
- SafePal reported order information tied to 39,798 customers was compromised.
- Exposed data includes names, emails, shipping addresses, phone numbers, and purchase details (useful for highly believable, targeted scams).
- SafePal says wallet credentials (seed phrases/private keys) were not part of the breach, but warns attackers may attempt to trick customers into handing them over.
- SafePal warned of multiple scam channels: phone calls, emails, texts, letters, refund offers, firmware-update requests, and fake customer support.
- SafePal says it has already taken down “over 30 fraudulent websites and phishing links” connected to the incident.
- The issue reportedly originated from a vulnerability in an order-tracking function that could expose other customers’ order information under certain conditions.
Who’s being targeted
- Commonly targeted roles: All Employees, Executives, Customer Support, IT/Security, Communications/PR.
- Affected industries: Cryptocurrency, Consumer electronics, Financial services (crypto users).
- Attack channels: email, website, vishing, smishing.
- Impersonated: SafePal Customer Support / SafePal Security Team, SafePal employee / SafePal Support, SafePal Refunds / SafePal Billing.
Awareness takeaways
- Treat breach-related outreach as suspicious, verify via official channels you navigate to yourself.
- Never share seed phrases, private keys, or wallet passwords, legitimate support should not ask for them.
- Do not click links or scan QR codes from unsolicited messages, even if they reference a real incident.
- Report suspicious messages, calls, letters, and websites quickly to limit harm to others.
Red flags to watch for
- Unsolicited message pressuring an urgent firmware update
- Includes a link/redirect instead of telling users to type the SafePal address manually
- Any request for seed phrase/private key/password (SafePal says it never requests this)
- Caller claims to be SafePal and asks for seed phrase/private key/password
- Creates urgency tied to the breach to push immediate compliance
- Requests sensitive information that SafePal explicitly says it never collects
- Unexpected refund message tied to a public incident
- Includes a link or QR code in an unsolicited text
- Pushes you to provide additional personal info beyond what a legitimate support process would require
Read the video transcript
If you use SafePal, scammers now know your name, email, and what you bought, because nearly 40,000 orders leaked. They’re using that info to send super convincing fakes, like an email from “SafePal Security” titled “Firmware Update Required,” with your real name and order details, pushing you to click a link and enter your seed phrase. Here’s the catch: SafePal says it will never ask for your seed phrase, private key, or wallet password, by email, text, phone call, refund offer, or firmware update request. If someone does, it’s a scam, no matter how real it sounds. Your move: if you get any SafePal message, don’t click or call back, open the official SafePal app or type the SafePal web address yourself and check there instead.