SafePal disclosed a vulnerability in its order tracking plug-in, and about 39,798 customer information was leaked.
SafePal disclosed that about 39,798 customers 'personal information and purchase information had been accessed without authorization after discovering that its plug-in used for order tracking had authorization flaws. The affected data involves customers who placed orders between March 2, 2025 and April 11, 2026.
The leaked information includes name, email address, shipping address, phone number and purchase details. Seed phrases, private keys, wallet passwords, bank account information, payment card numbers and government-issued ID numbers were not disclosed, and SafePal did not find any evidence that the vulnerability affected customers 'wallets or funds.
SafePal fixes an authorization vulnerability
that affects an order tracking feature associated with customer purchase information. Under certain conditions, this authorization flaw allows unauthorized parties to access other customers 'order records.
SafePal fixed the vulnerability after discovering it and introduced additional security controls. The company has also shortened the retention period of personal information in affected order-processing environments to 90 days and is hiring an independent security company to verify the effectiveness of the fixes while reviewing the entire system.
Affected customers received a separate notification from SafePal on August 16. The company also contacted logistics and distribution partners to confirm whether the leak had affected their systems.
Hardware wallet buyers face phishing risks
The leaked information provides attackers with enough customer-specific data to enable them to construct more deceptive impersonations. SafePal warns affected users to be wary of fraudulent phone calls, emails, text messages, physical letters, refund offers, fake firmware updates, malicious websites, and unexpected hardware deliveries that cite real purchase information.
The disclosure comes amid a data breach at ShipMonk earlier this month that exposed the personal information of 13,689 Trezor customers. The leak involved names and contact details related to hardware wallet delivery, but Trezor's device, private keys and wallet backup were not affected.
Hardware wallet security faced another technical threat this summer. The Bitcoin theft related to Coldcard may have reached 2,055 BTC, worth approximately $132 million, as attackers targeted seeds generated by vulnerable firmware versions. Galaxy Research has identified at least 15 independent attackers who have exploited the vulnerability.
More than 30 phishing websites have been closed
SafePal has identified and removed more than 30 fraudulent activities and phishing links related to this leak. While the independent security review is underway, surveillance of more malicious domain names continues.
Customers whose order information has been leaked do not need to transfer funds solely because of the leak. Anyone who has entered a seed phrase or private key in a suspicious website, message or other communication should treat the corresponding wallet as compromised and transfer the remaining assets to the newly generated wallet.
SafePal is directing affected customers to its dedicated support channels and informing users that any unexpected communications or hardware deliveries that cite their purchase history should be considered suspicious.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC