SafePal Confirms Order Data Breach Affecting 40,000 Customers; Wallet Credentials and Funds Remain Uncompromised
Key Takeaways
- •An authorization flaw in SafePal's order-tracking plugin allowed unauthorized access to order information for approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026.
- •The exposed data was limited to names, email addresses, shipping addresses, phone numbers, and purchase details, while seed phrases, private keys, wallet passwords, payment card numbers, bank account details, and government identification numbers remained secure.
- •SafePal stated that no evidence indicates the incident compromised access to its wallets or to customer funds.
- •Affected individuals were notified individually via email on August 16, and the company published a dedicated verification page and support channel for affected customers.
- •SafePal has fixed the flaw, engaged an independent third-party security firm to validate the fix and review its order-processing infrastructure, tightened personal data retention to 90 days, and removed more than 30 fraudulent websites and phishing links.

SafePal, a provider of cryptocurrency hardware and software wallet solutions that received early backing from Binance's investment arm Binance Labs in 2018, has confirmed a security incident stemming from an authorization flaw in an order-tracking plugin. The vulnerability, located in a plugin associated with customer order information, allowed unauthorized external access to order records under certain conditions. Approximately 39,798 individuals who placed orders between March 2, 2025 and April 11, 2026 were affected. Authorization failures of this type, known collectively as broken access control, have topped the OWASP Top 10, the industry's most widely cited ranking of web application security risks, since its 2021 edition.
According to the company's disclosure, the exposed data consists of names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal emphasized that more sensitive categories of information were not involved in the breach: seed phrases, private keys, wallet passwords, payment card numbers, bank account details, and government-issued identification numbers all remained secure. The company further stated that no evidence indicates the incident compromised access to SafePal wallets or customer funds.
All affected individuals were notified individually via email on August 16 from the address security@safepal.com, with a subject line indicating that their order information had been affected. SafePal has also published a dedicated verification page where customers can confirm their status using an order identification number and shipping country. Standalone verification pages of this kind are a standard anti-phishing measure in breach response, because notification emails themselves are frequently imitated by scammers.
Dear community, While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers. The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal), August 16, 2026
Company Response and Recommended Precautions
Following the discovery, SafePal remediated the authorization flaw and introduced supplementary security measures. An independent third-party security firm has been engaged to validate the fix and perform a comprehensive review of the broader order-processing infrastructure. The company has also contacted relevant logistics and fulfillment partners to confirm the issue had not spread further within their systems.
Additionally, the retention period for personal information within the affected environment has been tightened to 90 days, subject to applicable legal requirements, and a dedicated support channel has been established to ensure affected customers receive direct, tracked assistance. SafePal said progress on these ongoing measures will be disclosed through official company channels. The 90-day cap is consistent with the storage-limitation principle found in data-protection frameworks such as the European Union's General Data Protection Regulation, which requires personal data to be kept no longer than necessary for its intended purpose. For readers tracking the incident, the open items to watch are the independent review's findings and any further phishing takedowns, both of which the company has said will be communicated through its official channels.
The company has also identified and removed more than 30 fraudulent websites and phishing links tied to scam activities, with continued monitoring for emerging threats.
SafePal cautioned that exposed order details could be exploited in targeted social engineering campaigns, including fraudulent refund offers, fake firmware-update requests, and impersonation of customer support through phone calls, emails, text messages, physical mail, or unexpected hardware deliveries referencing a SafePal purchase.
Customers are advised to exercise caution with unsolicited communications, refrain from clicking links or scanning QR codes in unexpected messages, and manually enter the official website address (safepal.com) rather than following redirects. SafePal reiterated that it never requests seed phrases, private keys, or passwords through any communication channel under any circumstance.
Users who may have disclosed wallet credentials in response to suspicious outreach should treat the affected wallet as compromised, create a new wallet using an official SafePal device or application, transfer assets immediately, and contact the company through its official support channel.
Source: Metaverse Post