SafePal, a provider of hardware and software cryptocurrency wallets, has publicly disclosed a security incident in which unauthorized parties gained access to personal and contact details belonging to roughly 40,000 customers.
The company revealed the event on August 16, 2026, explaining that the exposure stemmed from a vulnerability in an order-tracking plugin used for customer purchases.
According to the disclosure, the flaw involved inadequate authorization controls.
Under certain conditions, it permitted outsiders to view another customer’s order records.
The compromised information covered individuals who placed orders between March 2, 2025, and April 11, 2026.
Exposed data included names, email addresses, shipping addresses, phone numbers, and specifics about the purchases themselves.
Approximately 39,798 customers were affected.Importantly, the breach did not touch the core elements that protect cryptocurrency holdings.
Seed phrases, private keys, wallet passwords, bank account details, payment card numbers, and government-issued identification were not accessed.
SafePal emphasized that it does not collect or store such sensitive credentials, and investigations found no indication that wallets or funds were compromised as a direct result of the incident.
Nevertheless, the company warned that the leaked order information creates elevated risks of targeted social engineering.
Attackers could use the details to craft convincing phishing attempts, impersonating SafePal staff via phone, email, text, or physical mail.
These schemes might offer fake refunds, firmware updates, replacement devices, or other assistance in an effort to trick users into revealing wallet credentials.
SafePal has already identified and removed more than 30 fraudulent websites and phishing links connected to the incident, and it continues to monitor for new ones.In response, the firm fixed the vulnerability and implemented additional security controls.
It has engaged an independent third-party security firm to validate the remediation and conduct a wider review of its order-processing systems.
Personal data retention in the relevant environment has been shortened to 90 days, subject to legal requirements.
All affected customers received individual email notifications from security@safepal.com on August 16, and a verification tool was launched allowing users to check their status with an order number and shipping country.
A dedicated support channel was also opened for those impacted.
SafePal advised customers never to share seed phrases, private keys, or passwords with anyone, including those claiming to represent the company.
Users should avoid clicking links in unsolicited messages, type official website addresses manually, remain alert to unexpected contact referencing their orders, and report suspicious activity through official channels.
If any credentials were already shared in response to a scam, the company recommends treating the wallet as compromised, creating a new one on a trusted device or application, and transferring assets promptly.
The incident highlights ongoing challenges in securing e-commerce systems even when core wallet technology remains intact. SafePal expressed regret to the community and committed to providing further updates as its investigation and remediation efforts progress.