SafePal said on Sunday that a security incident resulted in the disclosure of order information for approximately 39,798 customers, all of which were placed between March 2 and April 11 this year.
SafePal pointed out in a blog announcement: "This incident did not involve your mnemonic words, private keys, wallet passwords or other wallet credentials, nor did it involve bank account information, payment card numbers or government-issued identification numbers. SafePal never requests, collects, processes or stores such information from customers."
Under certain conditions, this vulnerability may allow unauthorized personnel to view other customers 'order information. SafePal said the issue has been fixed and the company has added more security controls to the affected systems.
SafePal reminds affected customers that fraudsters may use stolen order details to make phishing attacks appear more credible. The company has sent email notifications to customers whose data may be at risk. Customers can still determine for themselves whether further action is needed and should not rely solely on information in email notifications.
SafePal lists different ways in which fraudsters may exploit leaked information: Victims may receive misleading phone calls disguised as customer service, phishing emails, text messages, written letters, false refund offers, misleading software and firmware update requests, misleading information posing as customer service, or links to seemingly authentic phishing websites.
The company also warned that stolen order records could eventually be posted or disseminated to public online forums. "Please be vigilant about any unexpected contact or hardware delivery that mentions your SafePal purchase history, whether delivered by phone, mail or in person."
According to SafePal, customers do not need to transfer cryptocurrency to other wallets simply because order data is compromised. Assets need to be transferred only if the recovery phrase or private key is leaked in a suspicious website, email, text message, phone call or letter. If wallet credentials are compromised in some way, SafePal recommends treating the wallet as unsafe.
SafePal hired an independent security company and limited the retention period of personal order data to 90 days after fixing the bug. SafePal said the access control vulnerability has been fixed and additional security measures have been added to the order-related system. The company also hired an independent cybersecurity company to confirm that the fixes worked as expected. Not only will the outside company examine the original issue, it will also conduct a broader security review of SafePal's order processing system to identify other potential vulnerabilities.
SafePal also shortens the time customers 'personal information is retained in relevant order processing systems. The new retention period is 90 days, unless applicable law requires certain information to be retained for a longer period of time.
According to SafePal, they have confirmed which customers 'data was accessed and communicated directly with those customers to provide more details.
In addition, other companies that worked with SafePal to process order shipment and delivery were also involved in the investigation. SafePal requires these external partners to check their own systems for this security vulnerability, not just to SafePal's order environment.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following