NewsCryptoSafePal Says Order-Tracking Flaw Exposed Data From 39,798 Customers

SafePal Says Order-Tracking Flaw Exposed Data From 39,798 Customers

Author: CoinLineup·

Key Takeaways

  • SafePal reported that a flaw in its order-tracking system exposed data tied to 39,798 customers.
  • The company stated the incident involved order-related records and did not indicate that private keys or wallet balances were compromised.
  • SafePal disclosed the incident through its official security update page and did not confirm any wider breach beyond the order-tracking system.
  • Exposed order and contact data could still be leveraged for phishing or targeted attacks against cryptocurrency wallet holders.
  • The disclosure poses reputational risk for a hardware-wallet maker whose core value proposition is custody and security.
SafePal Says Order-Tracking Flaw Exposed Data From 39,798 Customers

SafePal said an order-tracking flaw exposed customer data tied to 39,798 people, in a disclosure the hardware-wallet maker framed as a data-exposure incident rather than a compromise of user funds.

What SafePal said about the order-tracking flaw

The account comes from SafePal’s own security update, which attributed the exposure to a flaw in its order-tracking system. For related coverage, see XRP Bridge Exploit Update: 198,715.88 XRP Stolen in Relayer Flaw.

The company put the number of affected customers at 39,798, a figure that centers on order records rather than any loss of wallet assets. For related coverage, see Fake Crypto Startup Fooled North Korean IT Workers, Cointelegraph Says.

SafePal described the issue as tied to order tracking, and the disclosure did not indicate that private keys or wallet balances were involved. For related coverage, see OCC Chief Says Crypto Firms Can Pursue U.S. Bank Charters.

What data was exposed and who was affected

The exposure was scoped to the group of customers linked to the order-tracking system, according to SafePal’s disclosure and follow-up reporting. For related coverage, see Coreum XRPL Bridge Loses Nearly 200,000 XRP After Relayer Flaw.

Because the incident stems from order records, the affected information is order-related customer data rather than the on-device secrets a hardware wallet is designed to protect. SafePal’s statement did not confirm a wider breach beyond that system.

Readers whose main concern is whether their personal details were involved should treat SafePal’s own notice as the authoritative scope, since the company has not detailed additional exposed fields beyond what its disclosure states.

Why the incident matters for SafePal and its customers

SafePal publicly acknowledged the flaw and issued its notice through its security update page, the step that made the customer count public in the first place.

A data-exposure event still carries weight even when funds are not directly at risk, because leaked order and contact data can feed phishing and targeting of wallet holders. The same dynamic surfaced when Israeli broker Bits of Gold investigated a third-party customer data breach, where the concern was exposed personal records rather than stolen crypto.

For a hardware-wallet brand, the reputational stakes are heightened because the product’s entire value proposition is custody and security, so any disclosure touching customer data tests user trust directly. That also makes the specific scope of the incident important: the public record so far points to order-tracking data, not to wallet access or device compromise.

The incident lands amid escalating pressure on wallet users, from data leaks through to physical wrench attacks that exploit knowledge of who holds crypto. That backdrop is part of why exposed customer records, and not just stolen keys, now shape how the sector weighs a breach.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.