In a recent update, non-custodial wallet SafePal said it has identified a security incident involving unauthorized access to customer order information during a specific time frame.
A flaw in the order-tracking plug-in led to unauthorized access to information of a subset of customers. SafePal noted that order information for customers who placed orders between March 2, 2025, and April 11, 2026, including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves about 39,798 customers.
All affected customers have been notified individually by email. The issue has been fixed with additional security measures introduced. A verification defect in the plugin for customers to track order progress has been identified and fixed.
SafePal noted that the security incident did not involve users’ seed phrases, private keys, wallet passwords, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers.
The wallet provider confirmed that hardware wallets, private keys, seed phrases, and crypto assets remain safe and unaffected. This is because cold storage architecture operates in an isolated environment, entirely separated from e-commerce servers. However, exposed order details may be used for phishing attempts.
What’s next?
SafePal outlined the affected information as including detailed purchase information such as users’ names, contact details, shipping addresses, and order details; hence, affected customers might be targeted by more sophisticated phishing attempts.
These attempts may include fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information.
In this light, SafePal urges all users to remain vigilant, as it will never ask for their 12/24-word recovery phrase, PIN, or private keys under any circumstances.
As the incident itself did not expose seed phrases, private keys, or wallet passwords, users might not need to move their assets. However, a crypto wallet may be compromised if the user has already shared or entered a seed phrase or private key in response to a suspicious message, website, phone call, or letter. If this is the case, they should create a new wallet and move their remaining assets immediately.







Be the first to comment