Key Points
- Nearly 39,798 SafePal customers had their personal information exposed through an order-tracking plugin vulnerability
- Compromised data consists of customer names, contact details, physical addresses, and transaction records
- Wallet security remains intactāno seed phrases, private keys, or cryptocurrency holdings were compromised
- More than 30 fraudulent phishing sites connected to this incident have been removed by SafePal
- SafePal plans to retain customer information for only 90 days and has engaged external security consultants
On August 16, cryptocurrency wallet company SafePal announced that a security vulnerability in its order-tracking plugin resulted in the exposure of personal information for roughly 39,798 users.
According to the company’s statement, an authorization weakness in the order-tracking plugin created conditions that permitted unauthorized individuals to view order information belonging to other customers.
The compromised data pertains to transactions processed from March 2, 2025, through April 11, 2026. Information exposed in the breach encompasses customer names, email contacts, telephone numbers, delivery addresses, and order histories.
SafePal emphasized that critical security elements including seed phrases, private keys, wallet access credentials, credit card details, banking information, and government identification documents remained protected.
The organization stated it found no indication that customer wallets or cryptocurrency assets were directly affected by this security incident.
How the Security Incident Unfolded
According to SafePal’s disclosure, the company received its first phishing complaint related to this issue in early May but initially classified it as a single occurrence. A comprehensive security audit was subsequently initiated, and by July the organization had begun reconstructing its order management infrastructure.
The underlying issueāthe authorization vulnerability within the plugināwas identified during July’s investigation. Customer complaints regarding phishing attacks featuring accurate personal information surfaced on Reddit and Trustpilot on July 3 and 4, significantly preceding SafePal’s public announcement.
Additionally, a configuration mistake resulted in the malfunction of an automated data-deletion routine from September 2025 through April 2026. While SafePal clarified this error didn’t enable the unauthorized access, it resulted in customer records being retained beyond their intended lifespan.
Phishing Threats Persist for Impacted Customers
The primary concern for affected users moving forward involves phishing attacks. Criminal actors armed with genuine customer information can create highly persuasive impersonation schemes.
SafePal cautioned that fraudsters may impersonate company representatives offering firmware patches, monetary refunds, or hardware replacements as a tactic to obtain wallet access credentials.
The company reports having successfully eliminated over 30 deceptive websites and phishing operations. Ongoing surveillance for additional fraudulent domains continues.
SafePal has contacted affected users via email and deployed a verification system enabling customers to determine if their purchase was impacted by entering their order reference number and shipping destination.
Users who may have already provided their seed phrase or private key to a questionable website should consider that wallet fully compromised, establish a new wallet immediately, and transfer any remaining cryptocurrency assets.
SafePal is contracting an independent cybersecurity firm to verify its security improvements and perform an extensive system evaluation. The company has also implemented a 90-day maximum retention policy for personal information within the affected system.
This security incident mirrors comparable situations at competing hardware wallet manufacturers. A third-party logistics breach recently compromised personal records of approximately 14,000 Trezor users. Earlier in the current year, Ledger wallet similarly informed customers about a data leak through its external e-commerce platform.
In all these instances, the manufacturers maintained that wallet functionality and private key security were never at risk.


