SafePal Data Breach Exposes Information of Nearly 40,000 Users

On August 16, SafePal disclosed that a vulnerability in an order-tracking plugin resulted in the exposure of customer order information for approximately 39,798 customers.

Summary

  • Approximately 40,000 SafePal customers had their order information leaked due to a software authorization defect.
  • The compromised records contained names, email addresses, shipping details, phone numbers, and specific purchase information.
  • Fortunately, sensitive information like seed phrases, private keys, and wallet passwords remained secure.
  • In reaction, SafePal took down over 30 phishing websites and has limited data retention to 90 days.
  • SafePal received a phishing report in May, leading to the discovery of the authorization flaw in July.

The compromised records relate to orders placed between March 2, 2025, and April 11, 2026, and include customer names, email addresses, shipping information, and descriptions of purchases. SafePal has reached out to each affected customer and has implemented a tool that allows them to verify their orders using their order number and shipping country.

The company ensures that seed phrases, private keys, wallet passwords, payment card data, bank account information, and government-issued IDs were unaffected. Additionally, SafePal stated there is no evidence to suggest that the incident compromised wallet access or customer funds.

SafePal Identified the Exposure as an Order-tracking Flaw

SafePal mentioned that the problem arose from an authorization defect in an order-tracking plugin, which, under specific conditions, permitted unauthorized access to another customer’s order details. The company has since rectified the issue and put additional access controls in place post-discovery.

The timeline outlined in SafePal’s incident FAQ suggests that the company first received a phishing report related to the matter in early May. Initially perceived as a singular occurrence, it escalated into a formal security investigation. By July, a comprehensive examination and complete overhaul of its order-processing system were underway, confirming the plugin flaw.

Data-retention Issues Extended the Affected Period

SafePal further revealed that a scheduled data-cleanup operation failed between September 2025 and April 2026 due to a configuration error. The company clarified that this malfunction did not result in unauthorized access but caused older order records to be retained longer than necessary, thus expanding the affected period back to March 2025.

SafePal has now confined personal data retention in the relevant order-processing environment to 90 days, as legally mandated. It has confirmed that the personal data of affected customers has been deleted from active e-commerce servers, while an encrypted offline copy will be kept for potential investigative needs.

Phishing Threats are Now the Primary Concern for Customers

The leaked information could enable cybercriminals to conduct more believable phishing scams utilizing real names, addresses, and order specifics. SafePal has already identified and taken down over 30 fraudulent websites and phishing links linked to scam activities and is actively monitoring for new threats.

This incident echoes other recent occurrences in the wallet industry. As reported by crypto.news, a third-party shipping breach previously exposed the personal data of 13,689 Trezor customers, including names, email addresses, phone numbers, and shipping details. Additionally, scammers have been sending out deceptive letters from Trezor and Ledger that contained QR codes intended to capture recovery phrases.

SafePal emphasized that it never requests customers’ seed phrases, private keys, or passwords. Customers are not obligated to transfer their assets solely due to the exposure of their order information. However, anyone who has input their seed phrase or private key on a suspicious website should consider their wallet compromised, create a new wallet, and relocate their remaining assets.

Next Steps

SafePal is currently working with an independent third-party security firm to validate its fixes and perform a thorough review of its order-processing systems. The identity of this firm has not yet been revealed. The company has also communicated with its logistics and fulfillment partners and has found no evidence suggesting that the breach reached their systems.

A dedicated support channel has been created, and SafePal is in contact with asset-tracing specialists for customers who report financial losses. However, it cautioned that this does not imply any admission of liability or commitment to compensation. The company has not yet identified the unauthorized party or provided a confirmed amount allegedly lost due to subsequent phishing attempts. Further information will be disclosed through official security updates.

  • Related Posts

    Everton vs Manchester United: Sunday Clash Predictions, Insights, and Free Betting Promotions in the Premier League

    MANCHESTER UNITED is preparing to capitalize on their recent success as they face an unbeaten Everton this Sunday. SunSport’s betting experts have delved into this significant encounter, offering crucial betting…

    Shein’s IPO Launch Reflects the Cost of Overlooked Growth Opportunities

    The long-awaited entry of Shein into the market has come at a complicated moment: the peak growth phase for the fast-fashion giant is over, and it now faces rising tariffs,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Everton vs Manchester United: Sunday Clash Predictions, Insights, and Free Betting Promotions in the Premier League

    • By admin
    • September 6, 2026
    Everton vs Manchester United: Sunday Clash Predictions, Insights, and Free Betting Promotions in the Premier League

    Shein’s IPO Launch Reflects the Cost of Overlooked Growth Opportunities

    • By admin
    • September 6, 2026
    Shein’s IPO Launch Reflects the Cost of Overlooked Growth Opportunities

    Two Scholars Honored with Lifetime Achievement Award at the 2026 NRF Awards

    • By admin
    • September 6, 2026

    Vesu Oracle Incident Results in $3 Million Liquidation Losses

    • By admin
    • September 6, 2026
    Vesu Oracle Incident Results in $3 Million Liquidation Losses

    UFC Fighter Exits Octagon Drenched in Blood as Shocked Fans Draw Parallels to a Crime Scene

    • By admin
    • September 6, 2026
    UFC Fighter Exits Octagon Drenched in Blood as Shocked Fans Draw Parallels to a Crime Scene

    The JSE Continues to Be a Key Element of a Diversified Investment Portfolio

    • By admin
    • September 6, 2026
    The JSE Continues to Be a Key Element of a Diversified Investment Portfolio