SafePal order-tracking data breach
Crypto-wallet maker SafePal disclosed that an authorization flaw in an order-tracking plugin let one customer view others' order records, exposing names, contact details and purchase information for about 39,798 customers without touching wallet keys or funds.
- Victim
- SafePal
- records
- 39.8K
- users
- 39.8K
On 16 August 2026, hardware- and software-wallet maker SafePal disclosed a data breach that exposed order information for approximately 39,798 customers. The breach resulted not from a wallet compromise but from an authorization flaw in an order-tracking plugin tied to the company's e-commerce order handling.
What happened
Under certain conditions, the flaw in the order-tracking function let one customer view another customer's order information โ an access-control failure rather than an external intrusion. The exposed data covered orders placed between 2 March 2025 and 11 April 2026 and included names, email addresses, shipping addresses, phone numbers and purchase details.
SafePal was explicit about what was not affected: seed phrases, private keys, wallet passwords, bank-account information, payment-card numbers and government-issued identification numbers were not involved, so customers' crypto assets were not at direct risk from the breach.
In response, the company remediated the vulnerability, engaged a third-party security firm for an audit, reduced its data-retention window to 90 days, and took down more than 30 phishing websites linked to the breach. All affected customers who placed orders in the vulnerable timeframe were notified individually by email from security@safepal.com.
Impact
- Order and contact data for about 39,798 customers exposed; the stolen dataset was also reported to be offered for sale.
- No wallet keys, credentials or payment data compromised; customer funds were not at direct risk.
- Elevated phishing risk, since attackers could pair a customer's identity and contact details with proof they own SafePal hardware.
Why it matters
For a crypto-wallet vendor, the danger of a breach like this is less about the data itself than about who the data identifies. A verified list of people who bought hardware wallets โ complete with names, addresses and phone numbers โ is a high-value targeting list for social-engineering and phishing campaigns aimed at draining wallets, which is why SafePal moved quickly to take down impersonation sites. The incident is a reminder that peripheral systems such as order tracking and e-commerce plugins can leak sensitive customer relationships even when the core product's cryptography is sound, and that broad access-control review and short data-retention are essential defences.
Timeline
Window of customer orders whose data was later found to be exposed via the vulnerable order-tracking plugin.
SafePal publicly discloses the breach affecting approximately 39,798 customers, says it has fixed the flaw, and notifies affected customers by email.
Sources
- coindesk.comhttps://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/08/17/safepal-data-breach-customer-order-information/
- rescana.comhttps://www.rescana.com/post/safepal-order-tracking-plugin-data-breach-exposes-39-798-customers-to-phishing-risk