Newsroom
16 August, 2026 / News / AI / Tags: safepal, plugin, order, customers, flaw

Hardware wallet firm reports authorization flaw in tracking plugin leaked names, addresses and purchase data; seed phrases and funds remain secure
Crypto wallet provider SafePal disclosed on August 16 that an authorization flaw in its order-tracking plugin allowed unauthorized access to personal order information belonging to approximately 39,798 customers. The company confirmed that the incident did not compromise wallet credentials, private keys or digital assets.
The affected records cover orders placed between March 2, 2025, and April 11, 2026. Exposed details include customer names, email addresses, shipping addresses, phone numbers and specific purchase information. SafePal stated that seed phrases, private keys, wallet passwords, payment card numbers, bank account data and government-issued identification numbers were not accessed. The firm also reported finding no evidence that the incident itself led to compromised wallet access or loss of customer funds.
SafePal’s hardware wallets and core services operate separately from its e-commerce systems. The company noted that its cold storage architecture remained isolated from the affected order-processing environment throughout the period.
SafePal traced the issue to an authorization defect in a plugin used to track customer orders. Under certain conditions the flaw permitted one party to view another customer’s order details. The company first received a phishing report consistent with the problem in early May. It initially treated the report as isolated before escalating the matter into a formal investigation. A full review of the order-processing pipeline in July confirmed the plugin vulnerability.
A separate configuration error caused a scheduled data-cleanup process to stop functioning correctly between September 2025 and April 2026. That failure did not create the unauthorized access but left older order records stored longer than intended, extending the window of affected data back to March 2025.
The technical defect has been resolved and additional access controls have been put in place. SafePal has reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal requirements. Affected customers’ personal information has been removed from active e-commerce servers, with an encrypted offline copy retained to support potential investigations.
All impacted customers were notified individually by email on August 16. SafePal also launched a verification tool that allows buyers to check their status using an order number and shipping country. The company has engaged an independent third-party security firm to validate the fix and conduct a broader review of its order-processing systems. It has contacted logistics and fulfillment partners and reported no evidence so far that the incident extended into their systems.
SafePal identified and removed more than 30 fraudulent websites and phishing links tied to scam activity linked to the exposed data. Monitoring for new domains continues. The firm has opened a dedicated support channel and is contacting on-chain asset-tracing specialists for any customers who report financial losses, while noting that this step does not represent an admission of liability or a commitment to compensation.
Because the leaked records contain genuine names, addresses and purchase details, affected customers face a heightened risk of targeted phishing and social-engineering attempts. These may take the form of deceptive emails, phone calls, text messages, fake refund offers, fraudulent firmware-update notices, customer-support impersonations or malicious websites.
SafePal reiterated that it never requests seed phrases, private keys, PINs or wallet passwords under any circumstances. Users who have already entered such credentials into a suspicious site or shared them in response to an unsolicited message should treat the affected wallet as compromised, create a new wallet and transfer remaining assets. The company advised all customers to remain vigilant and to disregard any communications or links that ask for recovery phrases or private keys.
Further updates are expected through SafePal’s official security channels as the independent review progresses.









