Quick Summary
- Nearly 39,798 SafePal customers had their information exposed due to an authorization vulnerability in an order-tracking plugin
- Compromised data includes customer names, contact information, delivery addresses, and transaction records
- Wallet security remained intact with no compromise to private keys, seed phrases, or cryptocurrency holdings
- Over 30 fraudulent websites connected to the incident have been shut down by SafePal
- New security measures include 90-day data retention limits and engagement of external security auditors
On August 16, cryptocurrency wallet service SafePal announced that a security vulnerability in its order-tracking system resulted in the exposure of personal information for roughly 39,798 users.
The security incident originated from an authorization weakness in the order-tracking plugin. This vulnerability enabled unauthorized individuals to access order information belonging to other customers under specific circumstances.
The compromised information pertained to transactions processed between March 2, 2025, and April 11, 2026. The leaked data encompasses customer names, electronic mail addresses, telephone numbers, delivery locations, and order specifics.
SafePal emphasized that sensitive security information including seed phrases, private keys, wallet authentication credentials, payment card data, banking details, and government identification documents remained protected and were not part of the breach.
The organization additionally stated that no evidence exists indicating any cryptocurrency wallets or customer assets were directly affected as a result of this security incident.
Incident Timeline and Discovery
According to SafePal, the first indication of trouble arrived through a phishing complaint in early May, which was initially categorized as an individual incident. A comprehensive security audit was initiated subsequently, and by July the organization had begun reconstructing its order-management infrastructure.
The underlying issue, the plugin’s authorization defect, was identified during the July security review. User complaints on Reddit and Trustpilot regarding phishing schemes containing precise personal information surfaced as early as July 3 and 4, considerably ahead of SafePal’s official announcement.
An additional technical misconfiguration resulted in the malfunction of an automated data-deletion routine between September 2025 and April 2026. While SafePal clarified this error did not facilitate the unauthorized access, it resulted in customer records being retained beyond their designated timeframe.
Ongoing Phishing Threats for Impacted Customers
The primary concern for affected individuals centers on phishing attacks. Malicious actors armed with authentic names, addresses, and purchase information can create highly persuasive social engineering campaigns.
SafePal cautioned that cybercriminals may impersonate company representatives offering firmware updates, monetary refunds, or product replacements as tactics to obtain wallet access credentials.
The company has successfully identified and removed over 30 counterfeit websites and phishing operations. Active monitoring for additional malicious domains continues.
SafePal contacted affected individuals through direct email communication and deployed a verification system enabling users to determine if their transaction was compromised by entering their order reference and shipping location.
Customers who may have already disclosed a seed phrase or private key on an unverified website should consider that wallet compromised, establish a new wallet immediately, and transfer any remaining cryptocurrency assets.
SafePal is engaging an independent external security consultancy to verify the effectiveness of implemented solutions and perform a comprehensive security assessment. The company has also implemented a 90-day maximum retention period for personal information in the affected system.
This security incident mirrors comparable situations at other hardware wallet manufacturers. A third-party logistics breach recently compromised personal information of approximately 14,000 Trezor users. Earlier in the current year, wallet manufacturer Ledger similarly informed customers about data exposure through its external e-commerce service provider.
In all instances, the manufacturers confirmed that wallet security and private key protection remained uncompromised.





