SafePal has disclosed a customer-data breach tied to its order-processing systems, according to CoinDesk. The crypto wallet provider said the incident exposed personal order information for 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. The exposed data included names, physical addresses and contact details, CoinDesk reports. SafePal said the incident did not compromise cryptocurrency funds, passwords, private wallet keys, seed phrases, bank account information, payment card numbers or government-issued IDs. According to CoinDesk, SafePal identified an “authorization flaw” in a plug-in used to track customer orders. SafePal said the flaw likely allowed attackers to view other customers’ orders, meaning the incident was centered on order visibility rather than the cryptographic controls that secure wallets. The distinction matters, but it does not make the incident harmless. Names, delivery addresses and contact details can be useful to attackers running phishing or impersonation campaigns, particularly against crypto users whose holdings may be attractive targets. CoinDesk reports that SafePal warned users who shared private keys or seed phrases through a phishing email, phone call or letter to treat the wallet as compromised and move assets to a new wallet. SafePal said it patched the vulnerability and added further security measures, according to CoinDesk. The company also said it notified affected customers by email from security@safepal.com on Sunday and hired an independent third-party security firm to audit the fix and review its order-processing systems. CoinDesk reports that SafePal also changed its data-retention posture for the affected system, saying it would keep customers’ personal data in its order-processing system for only 90 days from collection. The company said it had identified and removed more than 30 fraudulent websites and phishing links associated with the breach. Affected customers can use a verification tool on SafePal’s website to check whether their data was involved, SafePal said, according to CoinDesk. For now, the public record in this cluster rests on SafePal’s disclosure as reported by CoinDesk; there is no second source here independently confirming the customer count or the technical root cause. Who benefits: Affected customers benefit from a specific scope statement: SafePal says keys, seed phrases and funds were not affected. Attackers may benefit from the exposed contact and address data if they try to turn it into phishing or impersonation attempts. Who's exposed: The exposed group is limited, based on the current report, to 39,798 customers who placed orders in the stated date range. Customers who respond to phishing attempts by sharing private keys or seed phrases face the higher risk SafePal warned about.