SafePal says an order-tracking flaw exposed 39,798 customers' addresses
SafePal disclosed on 16 August that an authorisation flaw in an order-tracking plug-in exposed the names, addresses, phone numbers and purchase details of about 39,798 customers who ordered between March 2025 and April 2026.
Listen to this articleListen

SafePal disclosed on 16 August that an authorisation flaw in an order-tracking plug-in allowed one customer’s order information to be read by someone else, and that roughly 39,798 customers were affected. The exposed records belong to people who placed orders between 2 March 2025 and 11 April 2026, a window of thirteen months.
The company’s notice is precise about what was in those records: name, email address, shipping address, phone number and purchase details. It is equally precise about what was not. The incident “did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers”, and SafePal adds that it never asks for or stores those in the first place. On the question everyone asks first, the company’s wording is careful: “No evidence has been found that the incident itself compromised access to SafePal wallets or funds.”
What was taken, and what was not
| Field | In the exposed records | What it gives an attacker |
|---|---|---|
| Name, email, phone | Yes | Usable for targeted phishing |
| Shipping address | Yes | Usable for post and doorstep approaches |
| Purchase details | Yes | Identifies the device and the order |
| Seed phrase, keys, wallet credentials | No | SafePal: never requested, collected or stored |
| Bank details, card numbers, ID numbers | No | SafePal: never requested, collected or stored |
Why an address list is worse for a wallet maker than for a shop
A leaked customer list from a clothing retailer tells an attacker that somebody bought a coat. This one tells an attacker that a named person, at a specific address, with a working phone number, bought a device whose entire purpose is to hold cryptocurrency offline. That is a qualitatively different fact, and it is the reason this disclosure counts even though nothing was stolen.
SafePal’s own advice is the clearest statement of the risk, and it goes well beyond the usual line about suspicious emails. Customers are told to treat any unexpected contact or hardware delivery referencing their SafePal purchase as suspect, “whether it arrives by phone, in the post, or in person”. A wallet maker warning its customers about someone turning up at the door is not boilerplate. It is advice written for a leak that includes where people live.
The company also notes the affected information “might also be distributed on public forums”, which is the realistic end state for a dataset of this kind.
The flaw itself
SafePal describes it as an authorisation flaw in the order-tracking function for a plug-in tied to customer order information: “Under certain conditions, the flaw allowed unauthorized access to another customer’s order information.”
SafePal does not describe how the flaw was exploited, and the wording above is the whole of its technical account. What it describes is consistent with a broken object-level authorisation bug, the class of flaw where a system checks that you are signed in but never checks that the record you asked for is yours. That is our reading rather than the company’s.
The company is specific about something else, though, and it is the more useful fact: why the affected window runs back thirteen months. In the FAQ attached to the notice, SafePal says a scheduled data-cleanup process “had stopped working correctly between September 2025 and April 2026 due to a configuration error, which meant older order records stayed in the system longer than intended”. It adds that the fault “did not cause the unauthorized access itself, but it is why the affected range extends back to March 2025”. A retention job that silently stopped is what turned a flaw into thirteen months of exposed records.
What SafePal says it has done
The notice lists six completed steps and two continuing ones. The completed list: the flaw is fixed and further security measures added; the retention period for personal information in the order-processing environment is tightened to 90 days; a dedicated support channel is open for the incident; affected customers were emailed individually; third-party logistics and fulfilment partners were contacted to confirm the problem had not spread into their systems; and more than 30 fraudulent websites and phishing links tied to the resulting scam activity have been identified and taken down.
SafePal places the third-party firm under the completed heading, with the firm “is being engaged” to validate the fix. The two items it lists as continuing are following up with that firm on the audit, with any updates promised on the official blog, and monitoring for new fraudulent domains.
The 90-day retention change is the most durable item on that list, and it is tied directly to what went wrong: it is the same retention machinery whose failure stretched the exposure window. SafePal qualifies it as “subject to applicable legal requirements”. A shorter window shrinks the size of any future incident, which makes it the only step there that reduces the consequences of the next flaw rather than this one.
The signal arrived in May
The disclosure landed on 16 August, but the FAQ puts the first warning three months earlier. SafePal says it “first received a report consistent with this issue in early May, and treated it as an isolated case at the time, but escalated it into a formal security investigation”. It began “a full review and rebuild of our order-processing pipeline in July”, and confirmed the root cause during that work.
That sequence is worth stating because it sets what the disclosure date means. This was not a flaw found and announced in the same week. It was a report that looked like one customer’s problem in May, an investigation, a pipeline rebuild in July, and a confirmed cause announced in August.
How to check, and the trap to avoid
Affected customers were emailed on 16 August from [email protected] with the subject line “[Important] Your SafePal Order Information Has Been Affected”. SafePal has also published a verification page where a customer can check their status using an order ID and shipping country, which is the safer route: it does not depend on trusting an email that arrived unprompted.
One detail in the notice deserves repeating because it is the specific trick already in use against these customers. SafePal reports fraudulent websites that swap the lower-case L in its name for a capital i, two characters that look identical in many typefaces. The company’s instruction is to type the address manually rather than follow any link, including a link that appears to come from the notice itself.
The standing advice is unchanged and worth stating in full: SafePal will never ask for a seed phrase, private key or password, by phone, by email or through any other channel. Anyone who has already entered a seed phrase in response to a message, website, call or letter should treat that wallet as compromised, create a new one on a trusted device and move the remaining assets immediately.
Where this sits against the year’s thefts
No funds moved, so it stays out of the Crypto Exploit Tracker, which records incidents with losses attached.
What it does belong to is the smaller, less-tracked category of incidents that make future thefts easier rather than causing one. The Coldcard entropy sweep in July drained wallets directly. This one hands attackers a qualified list: people who own hardware wallets, verified by purchase, with addresses. For the wider picture of how the sector has been attacked this year, see our reference page on crypto security in 2026.


