SafePal Admits Security Flaw Exposed Data of Nearly 40,000 Wallet Users

0
2

Key Takeaways

  • An authorization flaw in SafePal’s order‑tracking plug‑in exposed personal data (names, emails, shipping addresses, phone numbers, purchase details) of roughly 39,798 customers.
  • No wallet credentials, private keys, seed phrases, or financial information were compromised; SafePal says there is no evidence that funds were accessed.
  • The exposed data could enable phishing, fraudulent calls, letters, or fake hardware‑delivery scams; customers are warned to treat unexpected contacts referencing their SafePal purchase as suspect.
  • A separate configuration error halted a scheduled data‑cleanup process, retaining older order records longer than intended and extending the exposure window to orders placed March 2 2025 – April 11 2026.
  • SafePal began investigating after an early‑May 2026 report, fixed the flaw in July 2026, and has instituted a series of remedial measures (90‑day data retention purge, third‑party validation, takedown of fraudulent sites, status‑check page, etc.).
  • Threat actors have advertised a dataset matching the exposed window on a cybercrime forum, though SafePal has not publicly commented on the listing.
  • No confirmed financial losses have been linked to the breach; SafePal urges anyone who suspects a loss to contact support and notes it is engaging on‑chain asset‑tracing specialists.

Overview of the Authorization Flaw
SafePal disclosed that a vulnerability in an order‑tracking plug‑in allowed unauthorized access to another customer’s order information under certain conditions. The flaw did not involve wallet credentials, private keys, seed phrases, or any financial data such as bank account or payment‑card numbers. Approximately 39,798 customers had their names, email addresses, shipping addresses, phone numbers, and purchase details exposed. SafePal emphasized that the incident did not compromise access to its hardware wallets or the funds stored within them.

Timeline and Scope of Exposure
The affected orders were placed between March 2 2025 and April 11 2026. SafePal clarified that these dates reflect when the orders were made, not necessarily the period during which the flaw was exploitable. The company has not disclosed when unauthorized access began or ended, how many parties accessed the records, or how the vulnerability was originally discovered. A separate configuration error that halted a scheduled data‑cleanup process between September 2025 and April 2026 caused older order records to remain in the system longer than intended, thereby extending the exposure window back to March 2025.

Risks to Affected Customers
Because the leaked records tie a named individual to a home address and a purchase, SafePal warned that affected customers may become targets of fraudulent phone calls, emails, text messages, letters, refund offers, firmware‑update requests, or fake customer‑support communications. The company advised customers to treat any unexpected contact or hardware delivery referencing their SafePal purchase as suspect, regardless of whether it arrives by phone, mail, or in person. Notably, the data does not include wallet addresses, balances, or any indication of what assets a customer holds.

Chainalysis Context on Crypto‑Related Crime
In a parallel development, blockchain analytics firm Chainalysis reported 46 violent incidents globally tied to crypto holders through late June, with over $30 million stolen. The firm noted a sharp rise in French cases—from a handful before 2025 to 30 by mid‑2026—linked to stolen tax records of cryptocurrency owners. Only 12 of the 46 attempts resulted in a payment, a success rate of 26 %, down from 49 % in 2025. Chainalysis observed that criminals increasingly view crypto holders as high‑value targets because their wealth is instantly and irreversibly transferable.

Discovery, Investigation, and Remediation
SafePal said the first report consistent with the issue arrived in early May 2026. Initially treated as an isolated case, the report was escalated to a formal security investigation, prompting additional protections. In July 2026, the company launched a full review and rebuild of its order‑processing pipeline, during which it confirmed the root cause of the flaw. SafePal has since implemented a series of remedial actions: the flaw has been fixed, personal‑information retention in the order‑processing environment has been reduced to 90 days (subject to legal requirements), affected records have been purged from active servers with a secured offline backup retained solely for potential investigations, an independent third‑party security firm has been engaged to validate the fix and review broader systems, third‑party logistics partners have been contacted to confirm the issue did not spread, over 30 fraudulent websites and phishing links tied to the scam have been taken down, and a status‑check page (requiring order ID and shipping country) plus a dedicated support channel have been published.

Threat‑Actor Activity and Public Response
A threat actor subsequently advertised a dataset on a cybercrime forum that cited the same order window and customer count. The listing was surfaced by DarkWebInformer on August 16, with the seller offering to share order IDs and shipping countries so buyers could verify the data against SafePal’s own verification tool. As of the time of writing, SafePal has not issued any statement about the listing on its blog, incident page, or X account, and it did not immediately respond to a request for comment.

Comparison with Prior Incidents and Current Status
The incident echoes earlier data‑exposure events in the hardware‑wallet space, such as Ledger’s December 2020 breach that leaked roughly 272,000 records containing postal addresses, names, and phone numbers. Subsequent research on a subset of those victims revealed increased spam, scams, phishing, and two reports of possibly tampered devices, along with heightened safety concerns. To date, neither SafePal nor mainstream outlets covering the breach have reported a confirmed financial loss stemming from the exposed data. SafePal has asked customers who believe they suffered a loss to contact its support channel and said it is engaging on‑chain asset‑tracing specialists to investigate any potential linkage.

Customer Guidance and Bottom Line
SafePal maintains that customers do not need to move assets solely because of the exposure. However, anyone who entered a seed phrase or private key in response to a suspicious message should treat that wallet as compromised. The company continues to monitor the situation, reinforce its security posture, and provide transparent updates to its user base. While the breach raised privacy and phishing risks, the absence of wallet‑credential compromise and the swift remedial steps taken suggest that the direct financial impact remains limited, though vigilance is advised.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here