SafePal Order-Tracking Flaw Exposes Data Of 39,798 Customers


SafePal has disclosed unauthorized access to personal and purchase information belonging to approximately 39,798 customers after identifying an authorization flaw in a plug-in used for order tracking. The affected records cover customers who placed orders between March 2, 2025 and April 11, 2026.

The exposed information included names, email addresses, shipping addresses, phone numbers and purchase details. Seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government-issued identification numbers were not exposed, while SafePal found no evidence that the breach provided access to customer wallets or funds.

SafePal Fixes Authorization Flaw

The vulnerability affected an order-tracking function connected to customer purchase information. Under certain conditions, the authorization defect allowed an unauthorized party to access another customer’s order record.

SafePal fixed the flaw after discovering it and introduced additional security controls. The company has also reduced the retention period for personal information in the affected order-processing environment to 90 days and is engaging an independent security firm to validate the fix and review the wider system.

Affected customers received individual notifications from SafePal on August 16. The company has also contacted logistics and fulfillment partners to determine whether the exposure extended into their systems.

Hardware Wallet Buyers Face Phishing Risk

The leaked information gives attackers enough customer-specific data to construct more convincing impersonation attempts. SafePal warned affected users about fraudulent calls, emails, text messages, physical letters, refund offers, fake firmware updates, malicious websites and unexpected hardware deliveries referencing genuine purchase information.

The disclosure follows a ShipMonk breach that exposed personal data belonging to 13,689 Trezor customers earlier this month. That breach exposed names and contact information tied to hardware-wallet deliveries while leaving Trezor devices, private keys and wallet backups unaffected.

Hardware-wallet security has also faced a separate technical threat this summer. Coldcard-linked Bitcoin thefts may have reached 2,055 BTC, worth roughly $132 million, after attackers targeted seeds generated by vulnerable firmware versions. Galaxy Research identified at least 15 separate attackers exploiting the weakness.

More Than 30 Phishing Sites Taken Down

SafePal has identified and removed more than 30 fraudulent websites and phishing links associated with scam activity surrounding the exposure. Monitoring for additional malicious domains is continuing while the independent security review proceeds.

Customers whose order information was exposed do not need to move funds solely because of the breach. Anyone who has already entered a seed phrase or private key into a suspicious website, message or other communication should instead treat that wallet as compromised and move remaining assets to a newly generated wallet.

SafePal is directing affected customers to its dedicated support channel and has told users to treat any unexpected communication or hardware delivery referencing their purchase history as suspicious.