[ Story · STORY ]

SafePal breach hits 40,000 customers

SafePal confirmed a data breach exposed personal info of nearly 40,000 customers, weeks after phishing reports surfaced.

STORY·August 16, 2026·3 min read·By Gintautas Nekrosius
A cracked padlock icon with small dots streaming out, on cream background with one red accent
A breach found weeks after the phishing started.

SafePal, the hardware and software wallet provider, confirmed a data breach exposed personal information belonging to nearly 40,000 customers. The company said it identified the root cause only recently, even though users had been posting online about targeted phishing attempts as early as July.

What SafePal disclosed

The number at the center of this is 40,000, the count of customers whose personal data SafePal says was exposed, according to The Block. SafePal has not detailed exactly what fields were taken, whether that's emails, names, order history, or something more sensitive, but the timeline is the more telling figure here. Customers were reporting phishing attempts tied to their SafePal accounts in July. SafePal says it found the root cause "recently," which puts the gap between first customer complaints and company confirmation at roughly a month or more. That's the lag that matters: a window where affected users were getting targeted messages without knowing why, and without the company yet able to tell them what had happened or what to do about it.

A wallet provider is a data company now

Wallet providers sell themselves on security, and SafePal's pitch has always centered on keeping keys and user data locked down. A breach that exposes tens of thousands of customer records undercuts that pitch directly, regardless of whether any funds were touched. Phishing campaigns built on real customer data are far more convincing than generic scam attempts, because they can reference actual purchases, actual wallet models, actual account details. That's why the July reports matter: attackers appear to have had usable data before SafePal had a public explanation. The lag between exposure and disclosure is the recurring failure mode across this industry. Companies detect fraud patterns from customer complaints well before they trace the breach internally, and the gap in between is exactly when phishing works best. A wallet provider holding customer PII is holding a target list, and the value of that list to attackers doesn't wait for a company's incident response timeline.

What to watch next

The next signal is whether SafePal publishes specifics: what data fields were exposed, how the breach happened, and whether it offers any remediation like credit monitoring or dedicated support for affected users. If SafePal stays vague on scope and mechanism, expect the phishing attempts already reported since July to continue and likely sharpen, since attackers now know their access window is public and customers are on alert. The other thing worth tracking is whether other wallet or exchange providers who shared vendors, mailing lists, or infrastructure with SafePal see similar phishing waves. Breaches at custody-adjacent companies rarely stay isolated to one brand's customer base.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy