Newsroom

SafePal Discloses Breach Exposing Order Details of Nearly 40,000 Customers

16 August, 2026   /   News   /  AI   /   Tags:  safepal, plugin, order, customers, flaw

SafePal Discloses Breach Exposing Order Details of Nearly 40,000 Customers

Hardware wallet firm reports authorization flaw in tracking plugin leaked names, addresses and purchase data; seed phrases and funds remain secure

Crypto wallet provider SafePal disclosed on August 16 that an authorization flaw in its order-tracking plugin allowed unauthorized access to personal order information belonging to approximately 39,798 customers. The company confirmed that the incident did not compromise wallet credentials, private keys or digital assets.

Scope of the Exposed Information

The affected records cover orders placed between March 2, 2025, and April 11, 2026. Exposed details include customer names, email addresses, shipping addresses, phone numbers and specific purchase information. SafePal stated that seed phrases, private keys, wallet passwords, payment card numbers, bank account data and government-issued identification numbers were not accessed. The firm also reported finding no evidence that the incident itself led to compromised wallet access or loss of customer funds.

SafePal’s hardware wallets and core services operate separately from its e-commerce systems. The company noted that its cold storage architecture remained isolated from the affected order-processing environment throughout the period.

While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers. The issue has been fixed with additional security measures introduced.
SafePal

How the Flaw Was Identified and Contained

SafePal traced the issue to an authorization defect in a plugin used to track customer orders. Under certain conditions the flaw permitted one party to view another customer’s order details. The company first received a phishing report consistent with the problem in early May. It initially treated the report as isolated before escalating the matter into a formal investigation. A full review of the order-processing pipeline in July confirmed the plugin vulnerability.

A separate configuration error caused a scheduled data-cleanup process to stop functioning correctly between September 2025 and April 2026. That failure did not create the unauthorized access but left older order records stored longer than intended, extending the window of affected data back to March 2025.

The technical defect has been resolved and additional access controls have been put in place. SafePal has reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal requirements. Affected customers’ personal information has been removed from active e-commerce servers, with an encrypted offline copy retained to support potential investigations.

Customer Notifications and Follow-Up Actions

All impacted customers were notified individually by email on August 16. SafePal also launched a verification tool that allows buyers to check their status using an order number and shipping country. The company has engaged an independent third-party security firm to validate the fix and conduct a broader review of its order-processing systems. It has contacted logistics and fulfillment partners and reported no evidence so far that the incident extended into their systems.

SafePal identified and removed more than 30 fraudulent websites and phishing links tied to scam activity linked to the exposed data. Monitoring for new domains continues. The firm has opened a dedicated support channel and is contacting on-chain asset-tracing specialists for any customers who report financial losses, while noting that this step does not represent an admission of liability or a commitment to compensation.

Elevated Phishing Risks

Because the leaked records contain genuine names, addresses and purchase details, affected customers face a heightened risk of targeted phishing and social-engineering attempts. These may take the form of deceptive emails, phone calls, text messages, fake refund offers, fraudulent firmware-update notices, customer-support impersonations or malicious websites.

SafePal reiterated that it never requests seed phrases, private keys, PINs or wallet passwords under any circumstances. Users who have already entered such credentials into a suspicious site or shared them in response to an unsolicited message should treat the affected wallet as compromised, create a new wallet and transfer remaining assets. The company advised all customers to remain vigilant and to disregard any communications or links that ask for recovery phrases or private keys.

Further updates are expected through SafePal’s official security channels as the independent review progresses.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.