2026 SafePal — order-tracking plug-in authorization flaw; 39,798 customers (addresses/phones)
Data compromised
Approximately 39,798 customers who ordered Mar 2, 2025–Apr 11, 2026: name, email, shipping address, phone number, purchase details. Seed phrases, private keys, wallet passwords, bank/card numbers, and government IDs NOT exposed per SafePal.
Technical writeup
Verified company disclosure — August 16, 2026. SafePal published a security update stating an authorization flaw in an order-tracking plug-in let unauthorized parties access another customer’s order information under certain conditions. Affected window: orders placed March 2, 2025–April 11, 2026; approximately 39,798 customers. Exposed fields: name, email, shipping address, phone, purchase details. SafePal states seed phrases, private keys, wallet passwords, bank accounts, payment cards, and government IDs were not involved and that no evidence shows wallets/funds compromised by the incident itself. All affected customers emailed from [email protected] (subject “[Important] Your SafePal Order Information Has Been Affected”); lookup via scam-protection page with order ID + shipping country. Remediation: fixed plugin, third-party audit engaged, 90-day retention tightened, logistics partners checked, 30+ fraudulent phishing sites taken down. Primary residual risk is targeted phishing/firmware-scam impersonation using order details.
Root cause
Authorization flaw in order-tracking plug-in allowed unauthorized access to another customer’s order information under certain conditions; remediated after discovery
References
- https://www.safepal.com/en/blog/security-update
- https://www.safepal.com/scam-protection
- https://x.com/SafePal/status/2088937173139812792
- https://sqmagazine.co.uk/safepal-data-breach-39798-customers/
- https://www.theblock.co/news/business/2026-08-16-wallet-provider-safepal-says-data-breach-exposed-personal-info-of-nearly-40000-customers-411934
- https://crypto.news/safepal-data-breach-exposes-details-of-40000-users/