SafePal, a cryptocurrency wallet provider, disclosed on Aug. 16 that an authorization flaw in an order-tracking plugin exposed the order information of approximately 39,798 customers. The company said the affected records included names, email addresses, shipping addresses, phone numbers, and purchase details.
The vulnerability allowed unauthorized access to another customer's order information under certain conditions. SafePal said it fixed the issue and introduced additional access controls after identifying it.
The affected orders were placed between March 2, 2025, and April 11, 2026. SafePal said it emailed affected customers individually and launched a tool for buyers to check if their orders were impacted using their order number and shipping country.
SafePal emphasized that seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government-issued identification numbers were not exposed. The company also said it found no evidence that the incident compromised wallet access or customer funds.
SafePal said it first received a phishing report consistent with the problem in early May. It initially treated the report as an isolated case before escalating it into a formal security investigation. In July, the company began a full review and rebuild of its order-processing pipeline and confirmed the plugin flaw during that investigation.
SafePal separately disclosed that a scheduled data-cleanup process stopped working correctly between September 2025 and April 2026 because of a configuration error. That failure did not cause the unauthorized access but left older order records stored longer than intended, extending the affected range back to March 2025. SafePal has now reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal requirements.
The exposed information could help attackers create more convincing phishing attempts using genuine names, addresses, and purchase details. SafePal said it has already identified and taken down more than 30 fraudulent websites and phishing links tied to scam activity and continues monitoring for new domains.
The risk resembles other recent wallet-industry incidents. As crypto.news reported, a third-party shipping breach exposed personal information belonging to 13,689 Trezor customers, including names, emails, phone numbers, and shipping addresses. In related coverage, scammers have also mailed fake Trezor and Ledger letters containing QR codes designed to steal recovery phrases.
SafePal stressed that it never asks customers for seed phrases, private keys, or passwords. It said users do not need to move assets solely because their order information was exposed. However, anyone who has already entered a seed phrase or private key into a suspicious website should 'treat that wallet as compromised,' create a new wallet, and transfer remaining assets.
SafePal said it is engaging an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems. The firm has not yet been named publicly. SafePal also contacted logistics and fulfillment partners and said it has found no evidence so far that the incident extended into their systems. The company has opened a dedicated support channel and says it is contacting on-chain asset-tracing specialists for customers reporting financial losses. SafePal cautioned that this 'does not represent any admission of liability or commitment to compensation.' It has not identified the unauthorized party or disclosed a confirmed amount lost through follow-on phishing.







