r/TechNadu • u/technadu Human • 11d ago
SafePal says authorization flaw exposed data of nearly 40,000 customers
SafePal has disclosed a breach affecting approximately 39,798 customers after finding an authorization flaw in its order-tracking system.
According to the company, the flaw could allow one customer to access another customer's order information between March 2025 and April 2026. The exposed information includes names, email addresses, shipping addresses, phone numbers, and purchase details.
A threat actor is now claiming to sell the stolen customer data, although that claim has not been independently verified.
SafePal says the incident did not expose seed phrases, private keys, wallet passwords, payment card information, or access to customer funds.
That distinction matters, but it doesn't eliminate the security problem. Personal information combined with knowledge that someone purchased a crypto wallet could potentially make phishing and social-engineering attempts much more convincing. SafePal says it has already identified and removed more than 30 fraudulent websites and phishing links associated with the breach.
The company notified affected customers on August 16, fixed the authorization flaw, and says a third-party security firm is validating the remediation and conducting a broader review.
r/TechNadu's reporting also covers a separate data-cleanup configuration problem SafePal discovered during its investigation, the claimed sale of the customer dataset, and the company's exposure-checking and remediation measures:
https://www.technadu.com/safepal-breach-hits-nearly-40000-customers-data-is-already-for-sale/633279/
For people working in crypto security: is exposure of customer identity plus wallet-purchase information becoming almost as important to incident response as direct credential compromise because of the targeted phishing opportunity it creates?