NewsCryptoSafePal Discloses Order-Tracking Flaw That Exposed Data of 39,798 Customers

SafePal Discloses Order-Tracking Flaw That Exposed Data of 39,798 Customers

Author: Crypto Adventure·

Key Takeaways

  • An authorization flaw in SafePal's order-tracking plug-in exposed personal and purchase information of roughly 39,798 customers who ordered between March 2, 2025 and April 11, 2026.
  • Seed phrases, private keys, wallet passwords, bank and card details, and government ID numbers were not exposed, and SafePal found no evidence the breach gave access to wallets or funds.
  • SafePal fixed the flaw, cut the data retention period to 90 days, engaged an independent security firm for review, and individually notified affected customers on August 16.
  • SafePal has removed more than 30 fraudulent websites and phishing links linked to the incident, warning that leaked order data enables more convincing impersonation and phishing attempts.
  • The disclosure follows a ShipMonk breach affecting 13,689 Trezor customers and Coldcard-linked thefts of up to 2,055 BTC, indicating hardware-wallet users face risks across vendor systems, fulfillment partners, and firmware.
SafePal Discloses Order-Tracking Flaw That Exposed Data of 39,798 Customers

SafePal, a hardware wallet maker backed by Binance whose devices are designed to keep cryptocurrency private keys offline, has disclosed that an authorization flaw in an order-tracking plug-in allowed unauthorized access to the personal and purchase information of approximately 39,798 customers. The affected records cover customers who placed orders between March 2, 2025 and April 11, 2026, according to the company's security update.

The exposed information included names, email addresses, shipping addresses, phone numbers and purchase details. Seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government-issued identification numbers were not exposed, and SafePal said it found no evidence that the breach provided access to customer wallets or funds.

SafePal Fixes Authorization Flaw

The vulnerability affected an order-tracking function connected to customer purchase information. Under certain conditions, the authorization defect allowed an unauthorized party to access another customer's order record.

SafePal fixed the flaw after discovering it and introduced additional security controls. The company has also reduced the retention period for personal information in the affected order-processing environment to 90 days and is engaging an independent security firm to validate the fix and review the wider system.

Affected customers received individual notifications from SafePal on August 16. The company has also contacted its logistics and fulfillment partners to determine whether the exposure extended into their systems, leaving the findings of the independent review and any partner-side impact as the disclosure's main open items.

Hardware Wallet Buyers Face Phishing Risk

Because hardware wallets hold keys offline, a leak of order data like this one does not itself provide a route to customer funds; the practical risk centers on social engineering aimed at persuading users to reveal seed phrases or install malicious software themselves. The leaked information gives attackers enough customer-specific data to construct more convincing impersonation attempts. SafePal warned affected users about fraudulent calls, emails, text messages, physical letters, refund offers, fake firmware updates, malicious websites and unexpected hardware deliveries referencing genuine purchase information.

The disclosure follows a ShipMonk breach earlier this month that exposed personal data belonging to 13,689 Trezor customers. That breach exposed names and contact information tied to hardware-wallet deliveries while leaving Trezor devices, private keys and wallet backups unaffected.

Hardware-wallet security has also faced a separate technical threat this summer. Coldcard-linked Bitcoin thefts may have reached 2,055 BTC, worth roughly $132 million, after attackers targeted seeds generated by vulnerable firmware versions. Galaxy Research identified at least 15 separate attackers exploiting the weakness.

Together, the recent incidents point to risks on several fronts for hardware-wallet users — vendor order systems, fulfillment partners and device firmware — rather than a single point of failure.

More Than 30 Phishing Sites Taken Down

SafePal has identified and removed more than 30 fraudulent websites and phishing links associated with scam activity surrounding the exposure. Monitoring for additional malicious domains is continuing while the independent security review proceeds.

Customers whose order information was exposed do not need to move funds solely because of the breach. Anyone who has already entered a seed phrase or private key into a suspicious website, message or other communication should instead treat that wallet as compromised and move remaining assets to a newly generated wallet.

SafePal is directing affected customers to its dedicated support channel and has told users to treat any unexpected communication or hardware delivery referencing their purchase history as suspicious.