TLDR
- An authorization flaw in SafePal’s order-tracking plugin exposed data on nearly 39,798 customers
- Exposed info includes names, emails, phone numbers, shipping addresses, and purchase details
- Private keys, seed phrases, and wallet funds were not affected
- SafePal took down over 30 phishing websites linked to the breach
- The company is now reducing personal data retention to 90 days and hiring an independent security firm
Crypto wallet provider SafePal disclosed on August 16 that a flaw in its order-tracking plugin exposed personal data belonging to approximately 39,798 customers.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
The breach was caused by an authorization defect in a plugin used to track orders. Under certain conditions, the flaw allowed unauthorized access to another customer’s order information.
The exposed records covered orders placed between March 2, 2025, and April 11, 2026. Affected data includes names, email addresses, phone numbers, shipping addresses, and purchase details.
SafePal confirmed that seed phrases, private keys, wallet passwords, payment card numbers, bank account information, and government-issued identification numbers were not exposed.
The company also said there is no evidence that any wallets or customer funds were directly compromised by the breach itself.
Timeline of the Breach
SafePal said it first received a phishing report consistent with the problem in early May but initially treated it as an isolated case. A full security investigation was launched later, and in July the company began rebuilding its order-processing pipeline.
The root cause, the authorization flaw in the plugin, was confirmed during that July investigation. Public complaints on Reddit and Trustpilot about phishing attempts using accurate personal details appeared as early as July 3 and 4, weeks before SafePal’s public disclosure.
A separate configuration error also caused a scheduled data-cleanup process to stop working correctly between September 2025 and April 2026. SafePal said this failure did not cause the unauthorized access but left older records stored longer than intended.
Phishing Risk Remains for Affected Users
The main risk for affected customers is now phishing. Attackers using real names, addresses, and order details can craft convincing impersonation attempts.
SafePal warned that scammers may pose as company employees offering firmware updates, refunds, or replacement devices in order to steal wallet credentials.
The company has already identified and taken down more than 30 fraudulent websites and phishing links. It continues to monitor for new domains.
SafePal emailed affected customers individually and launched a tool allowing users to check whether their order was involved using their order number and shipping country.
Anyone who has already entered a seed phrase or private key on a suspicious website should treat that wallet as compromised, create a new wallet, and move remaining funds.
SafePal is hiring an independent third-party security firm to validate its fix and conduct a broader review. It has also reduced personal data retention in the affected environment to 90 days.
This breach follows similar incidents at other hardware wallet providers. A third-party shipping breach recently exposed personal data on nearly 14,000 Trezor customers. Earlier this year, wallet maker Ledger also notified customers of a data exposure through its third-party commerce provider.
In each case, the companies said wallets and private keys remained secure.







