BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

SafePal security incident exposes order data of 39,798 customers

SafePal, a provider of non-custodial crypto wallets, reported that a technical vulnerability in its order-tracking plugin resulted in unauthorized external access to customer order details in

AnonymousCryptoCompass newsroom
August 16, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

SafePal, a provider of non-custodial crypto wallets, reported that a technical vulnerability in its order-tracking plugin resulted in unauthorized external access to customer order details involving nearly 40,000 individuals.

Order information compromised via technical flaw

The company discovered the security incident after identifying a flaw in the order-tracking plugin used on its e-commerce platform. This issue allowed unauthorized parties to access data belonging to customers who placed orders between March 2, 2025, and April 11, 2026. The compromised information includes names, email addresses, shipping addresses, phone numbers, and specific purchase details for 39,798 customers.

SafePal has stated that it notified all affected customers directly via email. The technical defect has now been resolved, and the company implemented additional measures to reinforce security around customer data. The vulnerability had permitted external access to order details but was unrelated to core wallet functions.

No wallet credentials, assets, or sensitive financial data affected

SafePal clarified that the breach did not impact users’ wallet seed phrases, private keys, wallet passwords, payment card numbers, government-issued identification numbers, or bank account information. The company’s cold storage architecture remains segregated from e-commerce platforms, ensuring that digital assets and wallet credentials are securely stored and were unaffected by the incident.

In an official message, SafePal emphasized that hardware wallets, private keys, and crypto assets remain secure because the compromised e-commerce systems are completely isolated from wallet services. Nevertheless, the disclosed customer contact information could increase the risk of targeted phishing or social engineering attempts.

The incident exposed order information such as users’ names, contact details, shipping addresses, and order specifics. As a result, those affected could face more sophisticated phishing attempts in the aftermath of the breach.

Increased phishing risk prompts user alert

With personal order information accessed without authorization, SafePal expects attempted scams in the form of deceptive phone calls, emails, text messages, fake refund offers, fraudulent firmware updates, customer support impersonations, and malicious websites. The company underscored that it will never request sensitive wallet credentials such as a 12/24-word recovery phrase, private key, or PIN in any circumstances.

To counteract these risks, SafePal advises all customers to maintain heightened vigilance and avoid sharing confidential wallet information, even in the event of receiving official-looking requests or urgent messages. Users are urged to disregard any communications or links prompting them to reveal wallet keys or recovery phrases.

While the incident did not directly compromise wallet passwords or private keys, the company recommends that any user who has shared their recovery phrase, PIN, or key in response to suspicious communications should immediately transfer their assets to a new wallet for optimal safety.

In light of these developments, SafePal’s experience highlights a broader market trend, where even in the most secure environments, customers remain a target for social engineering. As attention turns to more robust, decentralized, and user-controlled solutions, Wall Street has begun moving towards Web3 frameworks. Investors now utilize platforms like 1stepSwap to store shares of leading U.S. companies and precious metals directly in their crypto wallets. Through the tokenization of real-world assets and automated price-finding systems, these platforms eliminate the need for intermediaries, offering users enhanced control and transparency.

SafePal reiterates that users should not disclose recovery phrases, PINs, or private keys to anyone, and recommends that those who believe they may have shared sensitive information after a suspected phishing attempt create a new wallet and transfer their remaining assets as soon as possible.

The post SafePal security incident exposes order data of 39,798 customers appeared first on COINTURK NEWS.