SafePal breach hits 40,000 customers
SafePal confirmed a data breach exposed personal info of nearly 40,000 customers, weeks after phishing reports surfaced.

SafePal, the hardware and software wallet provider, confirmed a data breach exposed personal information belonging to nearly 40,000 customers. The company said it identified the root cause only recently, even though users had been posting online about targeted phishing attempts as early as July.
What SafePal disclosed
The number at the center of this is 40,000, the count of customers whose personal data SafePal says was exposed, according to The Block. SafePal has not detailed exactly what fields were taken, whether that's emails, names, order history, or something more sensitive, but the timeline is the more telling figure here. Customers were reporting phishing attempts tied to their SafePal accounts in July. SafePal says it found the root cause "recently," which puts the gap between first customer complaints and company confirmation at roughly a month or more. That's the lag that matters: a window where affected users were getting targeted messages without knowing why, and without the company yet able to tell them what had happened or what to do about it.
A wallet provider is a data company now
Wallet providers sell themselves on security, and SafePal's pitch has always centered on keeping keys and user data locked down. A breach that exposes tens of thousands of customer records undercuts that pitch directly, regardless of whether any funds were touched. Phishing campaigns built on real customer data are far more convincing than generic scam attempts, because they can reference actual purchases, actual wallet models, actual account details. That's why the July reports matter: attackers appear to have had usable data before SafePal had a public explanation. The lag between exposure and disclosure is the recurring failure mode across this industry. Companies detect fraud patterns from customer complaints well before they trace the breach internally, and the gap in between is exactly when phishing works best. A wallet provider holding customer PII is holding a target list, and the value of that list to attackers doesn't wait for a company's incident response timeline.
What to watch next
The next signal is whether SafePal publishes specifics: what data fields were exposed, how the breach happened, and whether it offers any remediation like credit monitoring or dedicated support for affected users. If SafePal stays vague on scope and mechanism, expect the phishing attempts already reported since July to continue and likely sharpen, since attackers now know their access window is public and customers are on alert. The other thing worth tracking is whether other wallet or exchange providers who shared vendors, mailing lists, or infrastructure with SafePal see similar phishing waves. Breaches at custody-adjacent companies rarely stay isolated to one brand's customer base.
