The SafePal incident affects approximately 39,798 customers, the company said, after an authorization flaw in its order tracking plugin was exploited. The data exposed was related to purchases and shipping details, not users' cryptocurrencies.

BleepingComputer SafePal notified customers on August 16, with the company's initial statement describing the issue as an issue with its order tracking system. The company is now investigating the possibility of targeted fraud based on the leaked information.
See also: Trezor Breach: Data Leak from Logistics Partner
What we know about the SafePal incident
SafePal says the flaw allowed unauthorized access to other customers' order information. The exploit involved the plugin used to track an order, not the systems that manage wallets. The company discovered the issue while rebuilding its ordering process in July.
The affected data includes names, email addresses, shipping addresses, phone numbers and purchase information, according to the report. The range of orders goes back to March 2, 2025, and is linked to a misconfiguration that had stopped the process of clearing old data.
The company claims that no recovery phrases, private keys, wallet codes, card numbers, bank details, government identification documents or other credentials were exposed. The isolation of the cold storage infrastructure from the e-commerce servers limits, according to SafePal, the possibility of direct access to wallets or funds.
SafePal clarified that the cleanup interruption did not cause access, but allowed older information to remain available for longer. Following the investigation, it removed the personal data from active servers and kept an encrypted offline copy only for possible investigation by authorities.
The company also says it has not found any evidence of a breach in external logistics partners. These statements reflect the current state of the investigation and do not imply that every message citing SafePal is authentic. The independent technical assessment is expected to add additional evidence.

The risk from exposed elements
The leak doesn't have to contain private keys to be dangerous. A combination of name, phone, address, and purchase can help a scammer craft a convincing message or phone call. SafePal says phishing emails and phone calls have already appeared that exploit the company's identity.
The company has identified and removed more than 30 fake websites and links associated with the scams. It warns that perpetrators may pose as SafePal employees or law enforcement officials, requesting a product return, refund, or urgent firmware upgrade.
Users who receive suspicious communication should report it as phishing, block the sender, and keep the message as evidence. In a phone call attempt, the safest course of action is to end the call immediately, without sharing information or confirming your home address.
Users should not click on links or scan QR codes from unexpected messages. SafePal never asks for a recovery phrase, PIN, private key or wallet code, and says its employees do not initiate phone calls to customers.
See also: Coldcard bug: Critical firmware issue linked to Bitcoin theft
Update, control and next steps
SafePal says it has fixed the authorization flaw, strengthened access controls and reduced the retention period for sensitive order data to 90 days, subject to legal requirements. It has also engaged an independent security firm to verify the fix and conduct a broader review of the systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Affected customers received an email from security@safepal.com with the subject line “[Important] Your SafePal Order Information Has Been Affected.” The company provides a verification tool where the user enters their order number and shipping country, but recommends manually typing in the safepal.com rather than following links in the email.

The SafePal incident does not require a device replacement or funds transfer, as the user has not disclosed any credentials. If someone provided a recovery phrase or private key in a suspicious message, they should consider the wallet compromised, create a new one from a trusted device, and immediately transfer the available funds.
See also: ShinyHunters data leaks: How they are linked to email scams
The SecNews technical team recommends increased caution with any communication mentioning a specific SafePal order. Leaked purchase details can make a scam more convincing, but is not in itself an indication that users' recovery phrases or cryptocurrencies have been compromised.
