SafePal on Sunday said a security incident exposed order information belonging to about 39,798 customers, with the orders placed between March 2nd and April 11th of this year.
Speaking via a blog post announcement, SafePal said:
“This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers. SafePal never requests, collects, processes or stores such information from customers.”
Under certain conditions, that weakness made it possible for an unauthorized person to view another customer’s order information. SafePal says the issue has since been fixed, and the company has added more security controls to the affected system.
SafePal warns affected customers that scammers may use stolen order details to make phishing attempts look legitimate
Email notifications were already sent out to customers whose data could be at risk from the cyber attack. Customers can still determine whether or not they should take any further actions by themselves rather than depending only on the information from the email notification.
SafePal mentions different ways in which the scammers could make use of the leaked information. The victims can receive misleading calls on the support service, phishing emails, messages in the text form, written mail, offers of fake refunds, misleading update requests for the software and firmware, misleading messages from the support staff or web links directing to phishing websites that appear to be authentic.
The company has also warned that the stolen order records could eventually be posted or circulated on public online forums.
“Treat any unexpected contact or hardware delivery referencing your SafePal purchase as suspect, whether it arrives by phone, in the post, or in person. “
According to SafePal, there is no need for the customers to transfer their cryptocurrency to other wallets solely because of their order data exposure. This happens only when the recovery phrase or the private key has been provided on a dodgy website or via email, text, phone call, or letter. In case the wallet credentials have been compromised in some way, then SafePal recommends that the wallet is considered unsafe.
SafePal hires an independent security firm and limits personal order data retention to 90 days after fixing the flaw
SafePal says the access-control weakness has already been repaired, while additional security measures have been added to the order system involved in the incident. The company is also hiring an independent cybersecurity firm to confirm that the fix works as intended. That outside firm will go beyond checking the original problem and will carry out a wider review of SafePal’s order-processing systems for any other security weaknesses.
SafePal has also shortened the amount of time customer personal information is kept inside the relevant order-processing system. The new retention period is 90 days, unless applicable laws require certain information to remain on file for a longer period.
According to SafePal, they have already identified who exactly had their data accessed and have communicated directly with those individuals to give them more details.
Also, other companies that cooperate with SafePal with regard to the shipment and delivery of orders were also involved in the investigation. SafePal asked these external partners to check their own system for the presence of the security vulnerability, and not only in the SafePal order environment.




Be the first to comment