Crypto wallet provider SafePal disclosed on Sunday that an authorization flaw in its order-tracking system allowed unauthorized access to the order information of approximately 39,798 customers, exposing personal details such as names, physical addresses, and contact information.
The breach affected customers who placed orders between March 2, 2025, and April 11, 2026, and stems from a defect in a plugin used to track customer orders. Under certain conditions, the flaw permitted one customer to view another customer's order information simply by manipulating the order number, the company said in a statement.
The exposed records included names, email addresses, shipping addresses, phone numbers, and detailed purchase information tied to SafePal products. The company stressed that seed phrases, private keys, wallet passwords, bank account information, payment card numbers, and government-issued identification numbers were not compromised.
SafePal said it has found no evidence that the incident itself compromised wallet access or customer funds. However, the company warned that the exposed data could be used for targeted phishing and impersonation attempts, as attackers armed with genuine names, addresses, and purchase details can craft more convincing fraudulent communications.
The company said it first received a phishing report consistent with the problem in early May. It initially treated the report as an isolated case before escalating it into a formal security investigation. In July, SafePal began a full review and rebuild of its order-processing pipeline and confirmed the plugin flaw during that investigation.
A separate data-retention failure widened the affected period. SafePal disclosed that a scheduled data-cleanup process stopped working correctly between September 2025 and April 2026 due to a configuration error. While that failure did not cause the unauthorized access, it left older order records stored longer than intended, helping extend the affected range back to March 2025.
SafePal has now reduced personal-data retention in the relevant order-processing environment to 90 days, subject to legal requirements. Affected customers' personal information has been removed from active e-commerce servers, while an encrypted offline copy is being retained to support potential investigations.
The company said it has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach, and continues monitoring for new domains. SafePal also emailed affected customers individually from its security address and launched a verification tool allowing buyers to check whether their orders were affected using their order number and shipping country.
SafePal said it is engaging an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems. The firm has not yet been named publicly. The company also contacted logistics and fulfillment partners and said it has found no evidence so far that the incident extended into their systems.
The company has opened a dedicated support channel and says it is contacting on-chain asset-tracing specialists for customers reporting financial losses. SafePal cautioned that this does not represent any admission of liability or commitment to compensation. It has not identified the unauthorized party or disclosed a confirmed amount lost through follow-on phishing.
Phishing Risk and Industry Context
The primary risk for affected users is follow-on phishing and social engineering. Attackers who know a person purchased a specific hardware wallet product can craft convincing fake support messages or shipping notices designed to extract credentials. SafePal stressed that it never asks customers for seed phrases, private keys, or passwords.
Users who have already entered a seed phrase or private key into a suspicious website should treat that wallet as compromised, create a new wallet, and transfer remaining assets, the company said. Users do not need to move assets solely because their order information was exposed.
The incident resembles other recent wallet-industry breaches. A third-party shipping breach previously exposed personal information belonging to 13,689 Trezor customers, including names, emails, phone numbers, and shipping addresses. Scammers have also mailed fake Trezor and Ledger letters containing QR codes designed to steal recovery phrases.
The breach follows a recent hack of Coldcard hardware wallets, in which an attacker reportedly stole at least $120 million in bitcoin. While the incidents do not necessarily point to a systemic weakness in hardware wallets, they demonstrate that no crypto-storage solution is entirely risk-free.
SafePal provides hardware wallets, mobile and browser wallets, and other crypto-management tools designed to help users store and manage digital assets. The company has expanded its consumer footprint over the past year through partnerships and product launches, which concentrates more personal data in one place and raises the stakes for operational security across its user base.
For crypto brands, breaches involving customer records carry reputational weight beyond the immediate data exposed. User trust hinges on the perception that a wallet provider can safeguard information as carefully as it safeguards keys.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.