SafePal has reported a SafePal data exposure incident tied to an order-tracking plug-in. The issue, the company says, exposed customer information for roughly 39,798 people, including names and contact details, as well as shipping addresses and purchase-related data.
Importantly, SafePal also states that the exposed records did not include wallet credentials or financial information. Still, because the leaked data links a named person to a home address and a purchase, the company warns customers to expect scams that may look highly targeted.
What information SafePal says was exposed
According to SafePal, an authorization flaw in an order-tracking add-on allowed unauthorized access to another customer’s order information under certain conditions. The company did not disclose the plug-in name, its vendor, or the affected version range.
The exposed data reportedly included:
- Customer names
- Email addresses
- Shipping addresses
- Phone numbers
- Purchase details tied to orders
SafePal emphasizes that the leaked records did not contain wallet credentials or sensitive financial identifiers such as seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification numbers.
Was anyone’s wallet compromised?
SafePal says it found no evidence that the incident itself compromised access to SafePal wallets or funds. In its statement, the company specifically points to what was not involved: the seed phrase, private keys, wallet password, and other wallet-related credentials.
The company’s message is that affected customers do not need to move assets solely because of the exposure. However, SafePal adds an important caveat: if someone entered a seed phrase or private key after receiving a suspicious message, that wallet should be treated as compromised.
Why the leaked data matters for scams
Even when cryptocurrency access credentials are not exposed, customer data can still be dangerous. SafePal notes that because the records tie a named individual to a home address and a purchase, malicious actors may use that information to make fraud attempts more convincing.
SafePal warned that affected customers may receive fraudulent:
- Phone calls
- Emails
- Text messages
- Letters
- “Refund offers”
- Requests for firmware updates
- Fake customer-support communications
The company’s guidance is straightforward: treat unexpected contact—or unexpected hardware deliveries referencing a SafePal purchase—as suspect, whether the message arrives by phone, in the mail, or in person.
Timeline: when orders were placed and when the issue was confirmed
SafePal reported that the affected orders were placed between March 2, 2025 and April 11, 2026. The company clarified that those dates refer to when orders were submitted, not necessarily the exact period when the flaw could be exploited.
SafePal did not state when unauthorized access began or ended, how many external parties may have reached the records, or how the authorization issue was originally discovered. It also noted that no CVE identifier has been assigned to the problem.
SafePal says the first report consistent with the issue reached it in early May 2026. At the time, it treated the matter as isolated, then escalated it into a formal security investigation. During the investigation and follow-up remediation, the company introduced additional protections and began a broader review and rebuild of its order-processing pipeline in July.
Remediation steps SafePal says it has taken
To address the exposure and reduce future risk, SafePal says it has implemented multiple measures. These include both technical fixes and changes to how long personal data remains in active systems.
- The flaw has been fixed, and additional security measures were introduced.
- Personal-data retention was reduced to 90 days (subject to applicable legal requirements) for the relevant order-processing environment.
- Affected records were purged from active servers, while a secured offline backup was retained only to support possible investigations.
- An independent third-party security firm is being engaged to validate the fix and review order-processing systems more broadly.
- Third-party logistics and fulfillment partners were contacted to confirm the issue did not spread within their environments.
- Over 30 fraudulent websites and phishing links related to scam activity were taken down.
- A verification and support mechanism was published: a status-check page that uses an order ID and shipping country, plus a dedicated support channel.
SafePal also told customers to verify unexpected messages using order information rather than trusting unsolicited claims from phone, email, or letters.
Phishing and scam chatter around the same period
The incident has attracted additional attention because phishing attempts were reportedly observed earlier. SafePal’s FAQ addresses why it took until August to confirm the cause behind phishing emails it received in May. The delay, as described by the company, appears tied to the process of validating the underlying authorization problem.
Separately, reporting described one customer who said they received a suspicious email, a letter, and a phone call claiming to represent SafePal. The coverage also noted there was no confirmed link between that specific phishing attempt and the order-data exposure.
In the broader ecosystem, blockchain analytics firm Chainalysis has argued that criminals increasingly target crypto holders because digital assets can be moved quickly and irreversibly. The firm’s commentary referenced violence and fraud attempts documented globally, with a portion resulting in successful payment—an indicator that these scams can be financially meaningful even when the underlying technical breach is limited.
More data-handling issues SafePal says it discovered
Beyond the plug-in authorization flaw, SafePal also reported a separate operational problem: a scheduled data-cleanup process appears to have stopped working correctly between September 2025 and April 2026, due to a configuration error.
SafePal stated that this cleanup issue did not cause the unauthorized access itself. However, it likely explains why the exposed range extended back to March 2025, since older order records remained in the system longer than intended.
Cybercrime forum activity reported after the incident
As part of the incident’s aftereffects, a threat actor reportedly advertised a dataset on a cybercrime forum that cites the same order window and a similar customer count. The listing was surfaced on August 16, and the seller offered to share order IDs and shipping countries so prospective buyers could check them using SafePal’s verification tool.
As of the reporting, SafePal had not publicly addressed the forum listing in its blog, incident page, or on its social media account.
How to protect yourself if you ordered a SafePal device
If you placed an order during the affected window, SafePal’s primary advice is to stay skeptical of unexpected outreach. Use the company’s status-check page (order ID and shipping country) and contact the official support channel rather than replying to unsolicited messages.
Also watch for common scam patterns that can accompany real data leaks:
- Refund offers or “verification” requests that arrive unexpectedly
- Firmware-update messages that pressure you to act immediately
- Phone calls or text messages claiming to be customer support
- Hardware deliveries accompanied by claims that you must confirm identity right away
And if you ever entered a seed phrase or private key in response to a suspicious message, treat the associated wallet as compromised and follow appropriate recovery and safety procedures.
Conclusion
The SafePal data exposure highlights how even “limited” incidents—where wallet credentials are not leaked—can still create real risk through targeted social engineering. SafePal says it fixed the authorization flaw, shortened personal-data retention, purged impacted records from active systems, and introduced additional protections.
For customers, the best next step is practical caution: verify order status through official tools, be wary of unexpected contact tied to a purchase, and treat any attempt to obtain seed phrases or private keys as a major red flag.
Source: https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html
