← SafePal

2026 SafePal — order-tracking plug-in authorization flaw; 39,798 customers (addresses/phones)

2026 39.8K records affected Share on X

Data compromised

Approximately 39,798 customers who ordered Mar 2, 2025–Apr 11, 2026: name, email, shipping address, phone number, purchase details. Seed phrases, private keys, wallet passwords, bank/card numbers, and government IDs NOT exposed per SafePal.

Technical writeup

Verified company disclosure — August 16, 2026. SafePal published a security update stating an authorization flaw in an order-tracking plug-in let unauthorized parties access another customer’s order information under certain conditions. Affected window: orders placed March 2, 2025–April 11, 2026; approximately 39,798 customers. Exposed fields: name, email, shipping address, phone, purchase details. SafePal states seed phrases, private keys, wallet passwords, bank accounts, payment cards, and government IDs were not involved and that no evidence shows wallets/funds compromised by the incident itself. All affected customers emailed from [email protected] (subject “[Important] Your SafePal Order Information Has Been Affected”); lookup via scam-protection page with order ID + shipping country. Remediation: fixed plugin, third-party audit engaged, 90-day retention tightened, logistics partners checked, 30+ fraudulent phishing sites taken down. Primary residual risk is targeted phishing/firmware-scam impersonation using order details.

Root cause

Authorization flaw in order-tracking plug-in allowed unauthorized access to another customer’s order information under certain conditions; remediated after discovery

References