EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SafePal data leaked, exposing nearly 40,000 user information

2026-08-17 00:10:39
Bookmark

SafePal discloses a privilege vulnerability in its order tracking plug-in, affecting nearly 40,000 users.

SafePal disclosed on August 16 that a privilege vulnerability in its order tracking plug-in resulted in the disclosure of order information of approximately 39,798 customers.

Event summary

The order information of nearly 40,000 SafePal customers was exposed due to software rights vulnerabilities. The leaked records include names, email addresses, shipping addresses, phone numbers and detailed SafePal purchase information. Mnemonics, private keys, wallet passwords, payment details and government ID numbers are not affected. SafePal has removed more than 30 phishing websites since the incident and shortened the retention period of personal data to 90 days.

Vulnerability Discovery and Response

SafePal received a phishing report related to this issue in May, and subsequently confirmed the privilege vulnerability during an investigation in July. Affected records cover orders from March 2, 2025 to April 11, 2026, including names, email addresses, shipping addresses, telephone numbers and purchase details. SafePal said it had notified affected customers individually via email on Sunday and launched a tool that allows buyers to check order information using order numbers and receiving countries.

The wallet provider emphasized that mnemonics, private keys, wallet passwords, payment card numbers, bank account information and government-issued ID numbers were not disclosed. SafePal also said there was no evidence that the incident itself compromised wallet access or the security of customer funds.

Root cause of vulnerability: Order tracking plug-in

SafePal said the problem originated from a permissions flaw in a plug-in used to track orders. Under certain conditions, the vulnerability allows unauthorized access to other customers 'order information. The company said it had fixed the vulnerability after it was discovered and introduced additional access controls.

SafePal provides a longer timeline in detailed FAQs. The company said it first received a fishing report consistent with the problem in early May. It was initially treated as an isolated incident, but was subsequently upgraded to a formal security investigation. In July, the company began a comprehensive review and reconstruction of the order processing process and confirmed plug-in vulnerabilities during the investigation.

Data retention errors expand impact

SafePal also disclosed that due to configuration errors, the data cleanup plan originally scheduled to be implemented from September 2025 to April 2026 failed to operate normally. The company said the mistake did not directly lead to unauthorized access, but caused old order records to be stored longer than expected, thus backdating the impact to March 2025. Currently, SafePal has shortened the retention period of personal data in the relevant order processing environment to 90 days (within legal requirements). The company said personal information of affected customers had been removed from active e-commerce servers, but an encrypted offline copy was retained to support potential investigations.

The main risk currently facing users: phishing attacks

The leaked information could help attackers use real names, addresses and purchase details to launch more deceptive phishing attacks. SafePal said it has identified and removed more than 30 fraudulent websites and phishing links related to fraudulent activities and continues to monitor new counterfeit domain names.

This risk is similar to other recent incidents in the wallet industry. SafePal emphasizes that the company will never ask customers for mnemonic words, private keys or passwords. Users do not need to transfer assets simply because order information is leaked. But any user who has entered mnemonic words or private keys on suspicious websites should "treat the wallet as compromised," create a new wallet and transfer the remaining assets.

Follow-up action

SafePal said it is hiring an independent third-party security company to verify its fixes and conduct a broader review of the order processing system. The company has not announced a specific name. SafePal also contacted logistics and distribution partners and said it has so far found no evidence that the incident affected their systems. The company has opened dedicated customer support channels and said it is contacting on-chain asset tracking experts for customers reporting financial losses. However, SafePal also warned that this "does not represent any liability determination or compensation commitment." Currently, the company has not identified unauthorized third parties and has not disclosed the amount of confirmed losses caused by subsequent phishing attacks. It is expected that the results of further investigations will be released through an official security update.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP