Summary SafePal’s order-tracking flaw exposed personal and purchase information belonging to approximately 39,798 customers while wallet credentials remained secure throughout. Scammers could
Summary
- SafePal’s order-tracking flaw exposed personal and purchase information belonging to approximately 39,798 customers while wallet credentials remained secure throughout.
- Scammers could exploit leaked customer details for targeted phishing attempts involving fraudulent replacement devices, refunds, firmware updates, and impersonation campaigns.
- SafePal removed over 30 phishing links, while similar customer-data exposures have also affected Trezor and Ledger through commerce infrastructure providers.
SafePal has confirmed that an authorization flaw in its order-tracking system exposed personal information belonging to approximately 39,798 customers. The affected records included names, email addresses, shipping addresses, phone numbers, and purchase details.
According to SafePal’s X post, the incident affected customers who placed orders between March 2, 2025, and April 11, 2026. However, the company reported that seed phrases, private keys, wallet passwords, and customer funds remained secure.
Bank information, payment card numbers, and government-issued identification were also outside the exposed dataset. Despite those protections, the leaked information creates another security concern for affected customers.
Also Read: Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs
Exposed Customer Details Raise Phishing Concerns
Attackers could combine personal and purchase details to create convincing phishing messages while impersonating SafePal representatives. Such attempts may involve fake refunds, firmware updates, or replacement hardware wallets designed to obtain sensitive wallet credentials.
SafePal warned customers to remain cautious when receiving unsolicited messages claiming to come from company representatives. Scammers possessing accurate order details could make fraudulent communications appear more credible.
For instance, attackers may claim that customers need replacement devices or important firmware updates. They could then direct victims toward fraudulent websites designed to collect wallet credentials.
SafePal has already identified and removed more than 30 fraudulent websites and phishing links connected with related scams. Additionally, the company has contacted asset-tracing specialists regarding customers who may report losses.
SafePal Investigation Traces Exposure to Order-Tracking System
SafePal received its first report matching the breach pattern in early May but initially considered it an isolated case. As concerns developed, the company expanded its investigation and began rebuilding its order-processing pipeline in July.
During that review, SafePal identified the authorization weakness responsible for exposing customer records. However, several important details surrounding the incident remain unclear.
SafePal has not disclosed when unauthorized access first occurred or when attackers initially obtained customer information. Moreover, the company has not revealed how many parties may have accessed the exposed records.
Public complaints involving suspected SafePal impersonators appeared before the company formally disclosed the breach. A July 4 Trustpilot review described scammers contacting a customer while possessing detailed personal and purchase information.
Additionally, a Reddit user reported a similar encounter on July 3 involving an alleged SafePal representative. The caller reportedly knew the customer’s name, address, phone number, email address, and previous order information.
Both reports referenced safepal.support, a fraudulent website allegedly used to promote replacement hardware wallets. SafePal reported that earlier investigations into suspicious activity had not uncovered evidence of a breach. The company later confirmed the order-tracking authorization flaw during its broader investigation.
Hardware Wallet Providers Face Growing Customer Data Risks
SafePal’s disclosure follows separate customer-data incidents involving other hardware wallet providers and their commerce infrastructure. Trezor recently reported a breach involving its shipping partner ShipMonk.
That incident exposed information belonging to nearly 14,000 customers. Names, phone numbers, shipping addresses, cities, and email addresses were among the affected information.
Ledger also notified some customers in January about another exposure involving commerce provider Global-e. Names and contact information belonging to customers who made certain purchases through Ledger’s website were affected.
Significantly, these incidents did not involve private keys or direct access to customers’ cryptocurrency wallets. However, exposed personal information can provide scammers with valuable material for targeted impersonation attempts.
SafePal maintains that its wallets and customer funds remained unaffected by the authorization flaw. Nevertheless, affected customers may face phishing risks because attackers potentially possess detailed personal and purchasing information.
Also Read: Crypto Market Gains as Bitcoin Holds $63,000 While HYPE and GPS Rally
The post SafePal Investigation Traces Exposure to Order-Tracking System appeared first on 36Crypto.