SafePal discloses a privilege vulnerability in its order tracking plug-in, affecting nearly 40,000 users.
SafePal disclosed on August 16 that a privilege vulnerability in its order tracking plug-in resulted in the disclosure of order information of approximately 39,798 customers.
Event summary
The order information of nearly 40,000 SafePal customers was exposed due to software rights vulnerabilities. The leaked records include names, email addresses, shipping addresses, phone numbers and detailed SafePal purchase information. Mnemonics, private keys, wallet passwords, payment details and government ID numbers are not affected. SafePal has removed more than 30 phishing websites since the incident and shortened the retention period of personal data to 90 days.
Vulnerability Discovery and Response
SafePal received a phishing report related to this issue in May, and subsequently confirmed the privilege vulnerability during an investigation in July. Affected records cover orders from March 2, 2025 to April 11, 2026, including names, email addresses, shipping addresses, telephone numbers and purchase details. SafePal said it had notified affected customers individually via email on Sunday and launched a tool that allows buyers to check order information using order numbers and receiving countries.
The wallet provider emphasized that mnemonics, private keys, wallet passwords, payment card numbers, bank account information and government-issued ID numbers were not disclosed. SafePal also said there was no evidence that the incident itself compromised wallet access or the security of customer funds.
Root cause of vulnerability: Order tracking plug-in
SafePal said the problem originated from a permissions flaw in a plug-in used to track orders. Under certain conditions, the vulnerability allows unauthorized access to other customers 'order information. The company said it had fixed the vulnerability after it was discovered and introduced additional access controls.
SafePal provides a longer timeline in detailed FAQs. The company said it first received a fishing report consistent with the problem in early May. It was initially treated as an isolated incident, but was subsequently upgraded to a formal security investigation. In July, the company began a comprehensive review and reconstruction of the order processing process and confirmed plug-in vulnerabilities during the investigation.
Data retention errors expand impact
SafePal also disclosed that due to configuration errors, the data cleanup plan originally scheduled to be implemented from September 2025 to April 2026 failed to operate normally. The company said the mistake did not directly lead to unauthorized access, but caused old order records to be stored longer than expected, thus backdating the impact to March 2025. Currently, SafePal has shortened the retention period of personal data in the relevant order processing environment to 90 days (within legal requirements). The company said personal information of affected customers had been removed from active e-commerce servers, but an encrypted offline copy was retained to support potential investigations.
The main risk currently facing users: phishing attacks
The leaked information could help attackers use real names, addresses and purchase details to launch more deceptive phishing attacks. SafePal said it has identified and removed more than 30 fraudulent websites and phishing links related to fraudulent activities and continues to monitor new counterfeit domain names.
This risk is similar to other recent incidents in the wallet industry. SafePal emphasizes that the company will never ask customers for mnemonic words, private keys or passwords. Users do not need to transfer assets simply because order information is leaked. But any user who has entered mnemonic words or private keys on suspicious websites should "treat the wallet as compromised," create a new wallet and transfer the remaining assets.
Follow-up action
SafePal said it is hiring an independent third-party security company to verify its fixes and conduct a broader review of the order processing system. The company has not announced a specific name. SafePal also contacted logistics and distribution partners and said it has so far found no evidence that the incident affected their systems. The company has opened dedicated customer support channels and said it is contacting on-chain asset tracking experts for customers reporting financial losses. However, SafePal also warned that this "does not represent any liability determination or compensation commitment." Currently, the company has not identified unauthorized third parties and has not disclosed the amount of confirmed losses caused by subsequent phishing attacks. It is expected that the results of further investigations will be released through an official security update.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following