Crypto wallet maker SafePal has disclosed a data breach tied to a flaw in its order-tracking system on its official blog and via a post on X. The company says wallets, seed phrases, and funds were never at risk, but customer contact and shipping details were.
Dear community,
— SafePal – Crypto Wallet (@SafePal) August 16, 2026
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures…
SafePal identified an authorization flaw in a plug-in used for tracking customer orders. Similar to a parcel-tracking page that lets one customer view another’s receipt just by changing the order number, the bug let unauthorized parties pull up other customers’ order records. The flaw is now patched and additional security measures are in place.
SafePal says it has taken down more than 30 fraudulent websites and phishing links linked to the incident and is bringing in an independent security firm to audit the fix.
The exposure covers orders placed between March 2025 and April 2026, and affects over 39,000 customers. Data accessed includes contact information and purchase/shipping. Seed phrases, private keys, wallet passwords, payment card numbers, bank details, and government IDs were not exposed, with no evidence that any wallets or funds were accessed.
All affected customers were notified individually by email. There’s a verification tool at safepal.com/scam-protection where customers check their status with an order ID and shipping country. Going forward, personal data in the order system will be retained for only 90 days. Full details are posted on SafePal’s official blog here.
Affected customers, and crypto users in general, should never share a seed phrase or private key with anyone, including people posing as SafePal or any other support, and should type web addresses in manually rather than clicking links in unsolicited messages. Anyone who has shared wallet credentials in response to a scam should assume that wallet is compromised and move funds to a new one immediately.
It serves as a reminder that even well-secured wallet cryptography can sit behind vulnerable business systems. Names, addresses, and phone numbers are enough to power convincing phishing through fake support calls, refund scams, or malicious “firmware update” links.

Leave a Reply