
SafePal Bitcoin Wallet Breach Exposes 40K Customer Records on Cybercrime Forum
A flaw in SafePal's order-tracking plug-in leaked the names, phone numbers, and shipping addresses of approximately 40,000 customers over a 14-month period. The stolen records are now being advertised for sale on cybercrime forums.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Vulnerability and Scope
Safepal, a bitcoin wallet provider, disclosed a security flaw in an order-tracking plug-in that exposed customer personal information. The breach affected approximately 39,798 to 40,000 customers, according to reports citing the company and cybercrime forum postings. Names, phone numbers, and shipping addresses were exposed over a 14-month window before the vulnerability was identified and closed.
Data Now on Cybercrime Market
The stolen records have surfaced on cybercrime forums, where a seller is advertising the file for purchase. The public posting of customer data on these platforms increases the risk that bad actors will use the information for targeted phishing, physical theft, or other fraud targeting wallet users and their holdings.
Risk Profile
Safepal customers face heightened exposure to physical security threats, given that attackers now possess both their names and home addresses. Hardware wallet users are often targeted by criminals who use this information to attempt theft of devices or social engineering attacks. The company has not yet published a detailed postmortem or timeline of when the vulnerability was first introduced or when it was patched.
Why It Matters
For Traders
SafePal users should assume their physical address is now public; consider moving hardware to a secure location and monitoring for targeted theft attempts.
For Investors
Wallet and custody providers face mounting pressure to adopt mandatory breach disclosure and insurance; SafePal's reputation damage may accelerate market consolidation toward larger competitors.
For Builders
Security audits of plug-in architectures and third-party integrations are now table stakes; many wallet projects lack formal threat modeling for information leakage vectors.
This article is for information only and is not financial advice. Read the full disclaimer.




