SafePal breach exposes data of nearly 40,000 customers, heightens phishing risk
SafePal has revealed that a security flaw in its e-commerce order-tracking system exposed personal details for just under 40,000 of its customers, significantly increasing the risk of targeted phishing and social-engineering attacks against affected users.
According to the company, the incident stems from an authorization vulnerability in an order-tracking plugin that allowed, under specific conditions, one customer’s order details to be accessed by another unauthorized party. SafePal publicly confirmed the breach on August 16, stating that order information for approximately 39,798 individuals was exposed.
What information was exposed
The compromised records relate to purchases made over a period stretching from March 2, 2025, through April 11, 2026. The leaked data includes:
– Full names
– Email addresses
– Shipping addresses
– Phone numbers
– Details of purchased products
This information is exactly the kind of dataset that can be weaponized by scammers to craft convincing phishing campaigns. Armed with accurate names, contact information, and specific purchase histories, attackers can send highly personalized messages that appear credible and relevant, making users more likely to click malicious links or divulge sensitive data.
SafePal stated that it contacted all identified affected customers by email on Sunday following the disclosure and has introduced a self-service tool that allows buyers to check whether their orders were part of the incident by providing their order number and shipping country.
What was not affected
SafePal has emphasized that the breach did not involve any core wallet security data. According to the company, the following types of information were not exposed:
– Seed phrases
– Private keys
– Wallet passwords
– Payment card numbers
– Bank account information
– Government-issued ID numbers
The firm said it has found no evidence that the vulnerability gave attackers any direct pathway to access wallets, compromise user funds, or interact with on-chain assets. In other words, the incident is currently assessed as an exposure of e-commerce and logistics data, not a direct compromise of the wallet infrastructure itself.
Despite this, the incident has serious security implications, mainly because leaked personal and order data can be used to trick users into voluntarily giving up their seed phrases or private keys.
How the vulnerability happened
SafePal traced the exposure to an authorization defect within a plugin used to power order tracking. Under certain circumstances, this flaw allowed unauthorized viewing of order records belonging to other customers.
After confirming the issue, the company says it has:
– Patched the vulnerable plugin
– Implemented stronger access controls
– Conducted a broader review of the affected order-processing components
SafePal has also published an incident FAQ outlining a more detailed sequence of events. According to that timeline, the first sign of trouble appeared in early May, when the company received a phishing report that later turned out to be consistent with this breach. Initially, the report was treated as an isolated case, but it was later escalated into a full security investigation as additional evidence emerged.
By July, SafePal had launched a comprehensive review and partial rebuild of its order-processing pipeline. During this more extensive internal audit, the team identified and verified the authorization flaw in the order-tracking plugin.
Data-retention issues made the breach worse
In a related disclosure, SafePal reported a separate but compounding problem: a scheduled data-cleanup routine had been malfunctioning between September 2025 and April 2026 due to a configuration error.
This retention failure did not cause the unauthorized accesses themselves. However, it meant that historical order data remained stored for far longer than originally planned, extending the time window of exposed records back to March 2025. Had the cleanup system worked correctly, fewer older orders would have been present in the affected environment, potentially limiting the scope of the incident.
In response, SafePal says it has now:
– Reduced customer-data retention in the relevant e-commerce environment to 90 days (except where longer storage is legally required)
– Removed affected customers’ information from active online e-commerce servers
– Kept only an encrypted offline archive of the relevant records for potential law-enforcement or regulatory investigations
Phishing: the primary danger for affected users
SafePal is framing the main risk from this incident as phishing and other forms of social engineering, rather than direct theft via compromised infrastructure.
The combination of a user’s real name, phone number, home address, email, and knowledge of what product they purchased enables scammers to craft messages that look authentic. For example, an attacker might:
– Pose as SafePal support, referencing a specific hardware wallet shipment
– Claim there is a “security update” or “order verification” needed
– Direct the user to a fake website that mimics SafePal’s interface
– Prompt the victim to enter their seed phrase or private key
Once a seed phrase or private key is entered into a malicious site or app, the attacker can immediately drain the associated wallet. SafePal reports that it has already identified and taken down more than 30 fraudulent websites and phishing links linked to this campaign and is continuing to monitor and block new scam domains as they appear.
Similar incidents across the hardware wallet industry
The SafePal breach is the latest in a series of incidents showing that even when core wallet systems remain uncompromised, peripheral services-such as shipping, e-commerce, and marketing platforms-can create serious privacy and security risks.
In an earlier case in the wallet sector, a third-party shipping provider leaked personal data for 13,689 customers of another hardware wallet brand. That exposure similarly included names, email addresses, phone numbers, and shipping addresses. Following that breach, scammers mailed physical letters and emails, some containing QR codes, attempting to trick users into entering recovery phrases on fake sites.
These patterns highlight a broader industry problem: while wallet providers typically invest heavily in securing keys and on-chain operations, customer data often flows through external plugins, vendors, and SaaS platforms that may not have security protections at the same standard as the core wallet product.
SafePal’s guidance to users
SafePal reiterates that it will never ask users to share seed phrases, private keys, or wallet passwords under any circumstances. The company specifically advises customers:
– Do not move funds solely because your order information was exposed; the breach alone does not give attackers access to your wallet.
– Treat any unsolicited message referencing your SafePal order, shipping details, or wallet purchase with extreme caution, especially if it urges “urgent” security actions.
– Double-check the authenticity of email senders, website addresses, and support channels before responding.
– If you have ever entered a seed phrase or private key into a website or app that you now suspect was fraudulent, treat that wallet as compromised without delay.
In the latter case, the recommended steps are:
1. Create a brand-new wallet with a fresh seed phrase.
2. Transfer any remaining assets from the compromised wallet to the new one as soon as possible.
3. Revoke any suspicious approvals or connected dApps associated with the old wallet, where applicable.
Company response and next steps
SafePal says it is working with an independent third-party security firm to validate the fix for the plugin vulnerability and to perform a broader review of its order-processing systems. The external firm has not yet been named publicly.
The company also reports:
– It has contacted its logistics and fulfillment partners and, so far, has found no evidence that the breach extended into their systems.
– A dedicated support channel has been opened for customers who suspect they have suffered financial losses due to related phishing attacks.
– On-chain asset-tracing specialists are being engaged to help affected users identify and, where feasible, trace stolen funds.
SafePal stresses that providing such assistance “does not represent any admission of liability or commitment to compensation.” At this stage, the company has not publicly identified the party responsible for the unauthorized access, nor has it released a confirmed figure for losses incurred through follow-on scams.
How affected users can protect themselves now
Even though wallet keys appear safe, exposed customers should take proactive steps to reduce their risk:
– Harden email security:
Enable two-factor authentication on the email account associated with your SafePal purchase. Many scams begin by compromising email, then resetting credentials on linked services.
– Use spam filtering and reporting:
Mark suspicious SafePal-related emails as spam or phishing. This trains your email provider’s filters and reduces the chance similar messages reach you again.
– Verify all “support” communications:
If you receive a message claiming to be from SafePal support, do not click links or share data immediately. Instead, access official support channels manually from a trusted app or bookmark and confirm that the communication is genuine.
– Scrutinize URLs and domains:
Phishing domains often imitate brand names with small variations, such as swapped letters or additional words. Always carefully inspect website addresses before entering any credentials.
– Be wary of urgent or alarming language:
Messages that claim your assets are “at immediate risk” and push you to act quickly are a hallmark of scams. Take time to verify through independent channels before acting.
What this means for the wider crypto ecosystem
The SafePal incident underlines a recurring challenge in the digital-asset space: the security of a crypto product is only as strong as the least-protected partner, plugin, or auxiliary service connected to it.
For users, this means:
– Privacy risks may arise even when your keys and wallets remain technically secure.
– Vendors handling shipping, marketing, or analytics data can become attractive targets for attackers.
– A comprehensive personal security posture now includes safeguarding not only seed phrases and private keys, but also your broader digital footprint-email, phone, and physical address data.
For companies, the breach highlights the need to:
– Conduct rigorous security and privacy reviews of third-party plugins and services.
– Minimize the collection and retention of personal data to reduce the blast radius of any future incident.
– Establish strong internal escalation procedures so early warning signs-like anomalous phishing reports-are quickly linked to potential systemic issues.
Moving toward better data minimization
One of the key lessons from this breach is the value of strict data minimization. The malfunctioning cleanup job that allowed older order records to persist dramatically widened the period of exposed data. Had the 90-day retention limit been effectively enforced from the beginning, far fewer users would now be at risk.
Going forward, both SafePal and the broader industry are likely to face growing scrutiny over how long non-essential customer data is stored in e-commerce environments and how effectively those retention policies are implemented in practice-not just documented on paper.
Long-term impact and user vigilance
The full impact of the SafePal breach may not be immediately visible. Phishing campaigns often unfold over months, with attackers slowly testing different lures and targeting strategies. Some victims may not connect a convincing scam email or text to a data leak that occurred many months earlier.
For that reason, affected users should maintain long-term vigilance, not just in the days immediately following a disclosure. Regularly reviewing wallet activity, keeping software up to date, and adopting a “never share your seed phrase” mindset are now baseline requirements for anyone holding digital assets.
While SafePal’s core wallet infrastructure appears intact, the incident serves as another reminder that in crypto, human error and social engineering often pose a greater threat than pure technical exploits. Protecting your identity, limiting the spread of your personal data, and treating every unsolicited “security alert” with skepticism remain some of the most effective defenses available to everyday users.
