Key Takeaways:
- About 39,798 users’ personal and purchase information were disclosed via a flaw in an order tracking plugin, according to SafePal.
- The incident affected orders placed between March 2, 2025, and April 11, 2026.
- While no seed phrases, private keys, wallet passwords, payment data and government IDs have been leaked, users are at a greater risk of being phished, says SafePal.
SafePal has announced a security breach with customer data related to purchased online orders, creating new phishing concerns for crypto users.
Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
The company has stated that it did not have its wallet infrastructure breached and that there is no personal data that gives users direct access to their cryptocurrency assets.
Order-Tracking Flaw Exposed Customer Data
SafePal states it happened because of a bug in an ordering tracking plugin for its ecommerce platform. This was because that section of customers was in a position to access the information, thanks to the vulnerability.
Around 39,798 consumers might have been impacted from March 2, 2025, to April 11, 2026.
The leaked information included customers names, e-mail address, shipping address, phone numbers, and purchase information. SafePal stated that it has reached out to affected users one by one through e-mail.
The company has additionally delivered a page online where consumers can examine if their details were included in the order by entering their Order ID and country of shipping.
Read More: Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Crypto Wallets and Private Keys Were Not Exposed
Seed Phrases Remain Outside the Breach
SafePal emphasized that it was not a seed phrase, private keys or wallet password leak. Details of bank accounts and payment cards or government identification were also not compromised, the company said.
These differences count a great deal for crypto users. The personal information on an order does not establish proof of identity or credentials to take control of the payment funds in a SafePal wallet.
Therefore, SafePal advised customers to pay more attention to phishing and impersonation activities, rather than rushing to transfer their assets.
Scammers may use legitimate names, addresses and buying details to forge legitimate messages. If not customers, attackers can pretend to be SafePal staff or customers’ delivery companies, or even Pacific support team, and ask customers to disclose wallet details.
Read More: Binance Blocks 11 Crypto Platforms in Major Compliance Move Affecting User Funds
SafePal Adds Security Measures
SafePal claims that this vulnerability has already been patched and further security measures have been added.
The company also reminds the users to be vigilant about unsolicited messages, emails and websites. Customers should never provide their seed phrase, private key or wallet password to anyone, even if the request appears to come from SafePal support.
SafePal has released a special scam-protection page for the hit customers and will be releasing additional information via its security channels.
The incident demonstrates a reoccurring vulnerability faced by hardware-wallet users: swept lines of customer data can provide researchers with a trick of what can essentially be a highly targeted attack.




Be the first to comment