The breach has impacted 39,798 clients who positioned orders between March 2, 2025 and April 11, 2026.
SafePal confused that the core safety of its wallets stays intact, including that customers’ seed phrases, non-public keys, financial institution passwords, checking account data, fee card numbers, and government-issued IDs weren’t affected.
Nevertheless, SafePal stated customers who’ve shared their non-public keys or seed phrases by way of a phishing e mail, telephone name, or letter ought to deal with their pockets as compromised and switch their belongings to a brand new pockets.
How SafePal is responding
The corporate stated it had patched the vulnerability and launched further safety measures in response. SafePal notified all affected clients by e mail from [email protected] on Sunday and employed an unbiased third-party safety agency to audit the repair and evaluate its order-processing methods.
SafePal additionally stated it will retain clients’ private knowledge in its order-processing system for under 90 days from the date of assortment. As well as, the corporate recognized and eliminated greater than 30 fraudulent web sites and phishing hyperlinks related to the breach.
Prospects can use a verification instrument on SafePal’s web site to test whether or not their knowledge was affected, the corporate stated.

