On August 16, SafePal disclosed that a vulnerability in an order-tracking plugin resulted in the exposure of customer order information for approximately 39,798 customers.
Summary
- Approximately 40,000 SafePal customers had their order information leaked due to a software authorization defect.
- The compromised records contained names, email addresses, shipping details, phone numbers, and specific purchase information.
- Fortunately, sensitive information like seed phrases, private keys, and wallet passwords remained secure.
- In reaction, SafePal took down over 30 phishing websites and has limited data retention to 90 days.
- SafePal received a phishing report in May, leading to the discovery of the authorization flaw in July.
The compromised records relate to orders placed between March 2, 2025, and April 11, 2026, and include customer names, email addresses, shipping information, and descriptions of purchases. SafePal has reached out to each affected customer and has implemented a tool that allows them to verify their orders using their order number and shipping country.
The company ensures that seed phrases, private keys, wallet passwords, payment card data, bank account information, and government-issued IDs were unaffected. Additionally, SafePal stated there is no evidence to suggest that the incident compromised wallet access or customer funds.
SafePal Identified the Exposure as an Order-tracking Flaw
SafePal mentioned that the problem arose from an authorization defect in an order-tracking plugin, which, under specific conditions, permitted unauthorized access to another customer’s order details. The company has since rectified the issue and put additional access controls in place post-discovery.
The timeline outlined in SafePal’s incident FAQ suggests that the company first received a phishing report related to the matter in early May. Initially perceived as a singular occurrence, it escalated into a formal security investigation. By July, a comprehensive examination and complete overhaul of its order-processing system were underway, confirming the plugin flaw.
Data-retention Issues Extended the Affected Period
SafePal further revealed that a scheduled data-cleanup operation failed between September 2025 and April 2026 due to a configuration error. The company clarified that this malfunction did not result in unauthorized access but caused older order records to be retained longer than necessary, thus expanding the affected period back to March 2025.
SafePal has now confined personal data retention in the relevant order-processing environment to 90 days, as legally mandated. It has confirmed that the personal data of affected customers has been deleted from active e-commerce servers, while an encrypted offline copy will be kept for potential investigative needs.
Phishing Threats are Now the Primary Concern for Customers
The leaked information could enable cybercriminals to conduct more believable phishing scams utilizing real names, addresses, and order specifics. SafePal has already identified and taken down over 30 fraudulent websites and phishing links linked to scam activities and is actively monitoring for new threats.
This incident echoes other recent occurrences in the wallet industry. As reported by crypto.news, a third-party shipping breach previously exposed the personal data of 13,689 Trezor customers, including names, email addresses, phone numbers, and shipping details. Additionally, scammers have been sending out deceptive letters from Trezor and Ledger that contained QR codes intended to capture recovery phrases.
SafePal emphasized that it never requests customers’ seed phrases, private keys, or passwords. Customers are not obligated to transfer their assets solely due to the exposure of their order information. However, anyone who has input their seed phrase or private key on a suspicious website should consider their wallet compromised, create a new wallet, and relocate their remaining assets.
Next Steps
SafePal is currently working with an independent third-party security firm to validate its fixes and perform a thorough review of its order-processing systems. The identity of this firm has not yet been revealed. The company has also communicated with its logistics and fulfillment partners and has found no evidence suggesting that the breach reached their systems.
A dedicated support channel has been created, and SafePal is in contact with asset-tracing specialists for customers who report financial losses. However, it cautioned that this does not imply any admission of liability or commitment to compensation. The company has not yet identified the unauthorized party or provided a confirmed amount allegedly lost due to subsequent phishing attempts. Further information will be disclosed through official security updates.





