SafePal, a hardware- and software-crypto wallet provider based in Singapore, says an authorization flaw in an order-tracking plug-in exposed the names, physical addresses, and contact details of 39,798 customers, though it insists no seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government IDs were compromised SafePal security update.
What the breach actually exposed
The leaked records covered customers who placed orders between March 2, 2025, and April 11, 2026, and included name, email address, shipping address, phone number, and order details such as the items purchased and delivery status SafePal security update. An attacker who exploited the flaw could have reconstructed a detailed purchasing profile for each affected customer — what they bought, where they live, and how to reach them — without ever touching the crypto assets sitting in their SafePal wallets.
How the order-tracking flaw worked
SafePal described the cause as an “authorization flaw” in the order-tracking function of a plug-in tied to customer orders. Under certain conditions, the flaw let an outsider pull up another customer’s order information — comparable to a parcel-tracking page that reveals one shopper’s receipt simply by changing the order number CoinDesk report. SafePal did not disclose whether it has identified how many outsiders actually exploited the flaw or whether the access was automated or manual.
SafePal’s response and the disclosure timeline
The company disclosed the incident on Sunday, August 16, emailing every affected customer from security@safepal.com with the subject line “[Important] Your SafePal Order Information Has Been Affected” SafePal security update. SafePal says it patched the vulnerability on discovery and added further security measures, then hired an independent third-party firm to audit the fix and review its order-processing systems. It will now keep personal data in its order system for only 90 days from collection and says it has taken down more than 30 fraudulent sites and phishing links tied to the breach. SafePal also published a verification tool on its website so customers can check whether their own order ID was exposed.
What affected customers should do now
The real risk is what happens next. Because the stolen records pair a real name, address, and phone number with proof that the person owns a crypto wallet, affected users face sharper phishing and impersonation attempts — fake support calls, refund offers, or firmware-update lures. SafePal warns that anyone who already shared a seed phrase or private key through a phishing message should treat that wallet as compromised and move assets to a fresh one.
For customers who have not shared credentials, the practical step is to scrutinize any email, call, or message that references a SafePal order — especially those arriving in the weeks after the disclosure — and to verify contact attempts through SafePal’s official website rather than any link or phone number in the message itself.
A wider pattern for crypto storage
The incident lands weeks after attackers reportedly drained at least $120 million in bitcoin from Coldcard hardware-wallet users CoinDesk report. It is a reminder that no storage method is risk-free and that concentrating holdings, or wallet choice, deserves a second look.
For teams weighing how data-handling mistakes ripple across an organization, the SafePal case shows why vendors are tightening retention and audit steps; NTT DATA’s rollout of AI coding tools to 9,000 employees shows a contrasting example of scaling internal data access under formal controls NTT DATA Codex rollout.
