Key Points Nearly 39,798 SafePal customers had their personal information exposed due to an authorization vulnerability in an order-tracking plugin Compromised data includes customer names, c
Key Points
- Nearly 39,798 SafePal customers had their personal information exposed due to an authorization vulnerability in an order-tracking plugin
- Compromised data includes customer names, contact information, delivery addresses, and transaction details
- Wallet security remains intact—no private keys, seed phrases, or cryptocurrency funds were compromised
- SafePal has removed over 30 fraudulent websites created following the security incident
- The wallet provider is implementing stricter data retention policies and engaging external security auditors
On August 16, SafePal, a cryptocurrency wallet service provider, announced that a security vulnerability in its order-tracking system resulted in unauthorized access to personal information of roughly 39,798 users.
The security incident stemmed from an authorization vulnerability within a plugin designed for order tracking. This defect permitted, under specific circumstances, unauthorized individuals to view order information belonging to other customers.
The compromised data pertains to transactions processed between March 2, 2025, and April 11, 2026. Information exposed in the breach includes customer names, email contacts, telephone numbers, delivery addresses, and order specifics.
SafePal emphasized that critical security elements including seed phrases, private keys, wallet access passwords, payment card credentials, banking details, and government identification documents remained protected and were not part of the data exposure.
Additionally, the company stated that no evidence suggests any cryptocurrency wallets or user funds were directly accessed or compromised as a result of this security incident.
How the Security Incident Unfolded
According to SafePal, the first indication of trouble came in early May when the company received a phishing complaint that aligned with the eventual problem, though it was initially handled as a single incident. A comprehensive security audit was subsequently initiated, and by July the company had begun overhauling its order-management infrastructure.
The underlying issue—the authorization flaw within the plugin—was identified during the July security review. User complaints on Reddit and Trustpilot regarding phishing attacks containing accurate personal information surfaced as early as July 3 and 4, several weeks prior to SafePal’s official public statement.
An additional technical error caused an automated data-deletion routine to malfunction from September 2025 through April 2026. While SafePal clarified this configuration issue did not enable the unauthorized data access, it resulted in customer records being retained beyond their intended storage period.
Ongoing Phishing Threats Targeting Affected Customers
The primary concern for impacted users is the heightened risk of targeted phishing campaigns. With access to genuine customer names, addresses, and purchase information, malicious actors can create highly persuasive fraud attempts.
SafePal cautioned that cybercriminals may impersonate company representatives offering bogus firmware upgrades, reimbursements, or device replacements to trick users into revealing their wallet access credentials.
The company has successfully identified and removed more than 30 fake websites and phishing operations. SafePal continues active surveillance for additional fraudulent domains.
SafePal has directly contacted affected customers via email and created a verification tool enabling users to determine if their purchase was impacted by entering their order reference number and shipping location.
Users who may have already provided a seed phrase or private key to a questionable website should immediately consider that wallet compromised, establish a new wallet, and transfer any remaining cryptocurrency assets.
SafePal is engaging an independent cybersecurity firm to verify the effectiveness of its remediation efforts and perform a comprehensive security assessment. The company has also implemented a new 90-day retention policy for personal data within the affected system.
This security incident is part of a concerning pattern affecting hardware wallet manufacturers. A third-party shipping contractor breach recently exposed customer information for approximately 14,000 Trezor users. Earlier in the year, competitor Ledger also informed customers about a data exposure originating from its third-party e-commerce platform.
Across all these incidents, the affected companies maintained that wallet functionality and private cryptographic keys were never compromised.
The post SafePal Security Incident: Plugin Vulnerability Compromises Data of 40,000 Users appeared first on Blockonomi.