SafePal, a prominent cryptocurrency wallet provider in India, announced a data breach exposing order information of almost 40,000 customers due to an authorization flaw in its order tracking system.

  • Nearly 40,000 Indian SafePal users affected by order data leak
  • No exposure of private keys, seed phrases, or wallet passwords
  • SafePal acted swiftly to fix flaw and remove fraudulent sites

What happened

SafePal disclosed that an authorization flaw in its order tracking system led to unauthorized access to the order information of approximately 39,798 customers. This vulnerability existed for over a year, from March 2, 2025, until April 11, 2026. The compromised data included personal details such as names, addresses, and purchase information linked to customer orders.

The breach, however, did not extend to more sensitive security credentials like seed phrases, private keys, wallet passwords, or financial account details, which are essential for controlling crypto assets. The company was able to identify and address the flaw after discovery and took immediate action to enhance their security measures.

Why it matters

Even though the core security assets that control cryptocurrency wallets were not compromised, the exposure of customer order data opens avenues for phishing, impersonation, and other social engineering attacks targeting SafePal users. Personal information like names and addresses can be exploited to craft convincing fraudulent communications.

Incidents like this highlight ongoing security challenges within crypto infrastructure providers operating in India’s growing digital asset market. Users rely heavily on wallet providers to maintain robust security both for wallet access and associated data handling to prevent reputational damage and loss of consumer trust.

What to watch next

SafePal has stated it has implemented a patch to close the authorization gap and introduced stricter security controls, including limiting retention of customer personal data in order processing systems to just 90 days. Monitoring if these measures effectively prevent recurrence will be key for stakeholders.

Additionally, SafePal reported the takedown of over 30 fraudulent websites and phishing links connected to the breach, signaling ongoing efforts to protect users from secondary attacks. The wider crypto community and Indian regulators may increase scrutiny on security practices of wallet providers following this incident.

Source assisted: This briefing began from a discovered source item from Economic Times Tech. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings