SafePal discloses order-data exposure tied to authorization flaw
Security & Exploits ·
The wallet maker says unauthorized access hit customer order records from orders placed between March 2, 2025 and April 11, 2026, affecting roughly 39,798 accounts.
SafePal has confirmed that a flaw in the order-tracking function of a plug-in tied to customer order data allowed outside parties to view another customer's order details under certain conditions, according to the company's security update. The exposed fields include names, email addresses, shipping addresses, phone numbers, and purchase details, but the company says the incident did not touch seed phrases, private keys, wallet passwords, bank details, card numbers, or government identification, and it has found no evidence that wallets or funds were compromised.
The scale of the exposure is put at approximately 39,798 customers, a figure that has been repeated across multiple reports on the incident, including coverage from wublockchain.xyz. SafePal says it began notifying affected users individually by email from security@safepal.com on August 16th, with the subject line "[Important] Your SafePal Order Information Has Been Affected," and has set up a webpage where customers can check their status using an order ID and shipping country.
Because the leaked data includes contact and shipping information alongside purchase history, SafePal is warning that affected customers could face more convincing phishing attempts than usual, ranging from fake phone calls and refund offers to spoofed firmware-update requests or fraudulent support messages designed to extract wallet credentials. The company reiterates that order exposure alone should not require customers to move assets, but it advises anyone who has already entered a seed phrase or private key into a suspicious site, message, or call to treat that wallet as compromised, create a new one through an official SafePal device or app, and transfer remaining holdings immediately.
On remediation, SafePal states it has fixed the underlying flaw, added unspecified additional security measures, and is engaging an independent third-party security firm to validate the fix and conduct a wider review of its order-processing systems. It also says it has shortened how long personal information tied to orders is retained.
What remains unclear is how the authorization flaw was discovered, how long it was active before detection, and whether any phishing campaigns tied to the leaked data have already surfaced. The outcome of the third-party security review, along with any further findings on the plug-in involved, has not yet been disclosed.