SafePal disclosed that an authorization flaw in an order-tracking plug-in exposed order information for 39,798 hardware-wallet customers who placed orders between March 2, 2025 and April 11, 2026. The exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details, while seed phrases, private keys, wallet passwords, payment card data, bank account information, and government IDs were not exposed. SafePal said it first received a report consistent with the issue in early May 2026, initially treated it as isolated, and later completed a broader review and rebuild of its order-processing environment.
The company also said a separate configuration error broke a scheduled data-cleanup process between September 2025 and April 2026, causing customer records to remain far longer than its stated retention period and expanding the scope of exposed data. SafePal has since purged personal data from active e-commerce servers, reduced retention in the order-processing environment to 90 days, launched a status checker, and engaged an independent third party to review the fix. The stolen data is reportedly being offered for sale on a cybercrime forum, and SafePal warned that attackers have already used real order details in targeted phishing and social-engineering calls and emails against affected customers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
As part of its response, SafePal launched an online verification tool for customers to check whether an order was affected and purged personal data for affected orders from active e-commerce servers. It said an encrypted offline copy would be retained for potential law-enforcement investigations and that retention in the order-processing environment was reduced to 90 days.
On August 16, 2026, SafePal publicly disclosed that approximately 39,798 customers were affected and emailed impacted users with the subject line "[Important] Your SafePal Order Information Has Been Affected." The company said names, email addresses, shipping addresses, phone numbers, and purchase details were exposed, but not seed phrases, private keys, or payment card data.
In July 2026, SafePal began a full review and rebuild of its order-processing system. During this work, it identified the authorization flaw in an order-tracking plug-in and moved to remediate it.
A SafePal support email dated May 19, 2026 told a customer that shipping and order data would be automatically deleted soon. This later contrasted with the discovery that cleanup failures had retained records longer than intended.
SafePal said it first received a report consistent with the issue in early May 2026 but initially treated it as an isolated case. The company's later investigation connected it to a broader exposure of customer order data.
Customers reported phishing emails and phone calls tied to SafePal in May, including messages claiming a wallet firmware update was required. One customer said the caller posed as a SafePal employee and the outreach referenced real order details.
SafePal said the exposed dataset covered customers who placed orders through April 11, 2026. This date marked the end of the order window tied to the disclosed breach.
SafePal said a separate configuration error caused its scheduled data-cleanup process to stop functioning correctly between September 2025 and April 2026. This left customer order records in the system longer than the company's intended retention period.
SafePal said the breach affected customers who placed orders starting on March 2, 2025. Exposed order data ultimately covered names, contact details, shipping addresses, and purchase information for orders in the affected period.
A threat actor claimed on a cybercrime forum to be selling the stolen SafePal customer data, citing the same affected order period and roughly 39,798 customers disclosed by the company. The seller reportedly offered order ID and shipping country details as proof, though possession of the data was not independently verified.
SafePal said it had taken down more than 30 fraudulent websites and phishing links connected to scam activity exploiting the exposed order data. The company also warned attackers were using lookalike domains to impersonate SafePal in phishing campaigns.
SafePal said it fixed the authorization flaw in the order-tracking function and implemented additional security measures. The company also engaged a third-party security firm to validate the fix and review the broader order-processing environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityweek.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcethecybersecguru.com
Open sourcesafepal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.