"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal said.
Scale of the exposure: 39,798 customer records and what they contained
SafePal disclosed that an authorization flaw in an order‑tracking plug‑in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The company said the exposed records did not include wallet credentials or financial information and that it has found no evidence the incident itself compromised access to SafePal wallets or funds. Affected orders were placed between March 2, 2025, and April 11, 2026; SafePal emphasized those dates describe when the orders were placed rather than the period during which the flaw may have been exploitable.
How the flaw and data‑retention error combined
SafePal said the immediate cause was an authorization flaw in an order‑tracking plug‑in that, under certain conditions, allowed unauthorized access to another customer's order information. The company did not name the plug‑in, its vendor, or the version affected, and no CVE identifier has been assigned. Separately, SafePal found a scheduled data‑cleanup process had stopped working correctly between September 2025 and April 2026 because of a configuration error; the company said that retention failure did not cause the unauthorized access itself but is why the affected range extends back to March 2025.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTimeline: reporting, investigation, and remediation actions
SafePal said the first report consistent with the issue reached it in early May 2026 and that the company initially treated that contact as an isolated case. The firm escalated the matter into a formal security investigation, introduced additional protections, and began a full review and rebuild of its order‑processing pipeline in July, confirming the root cause during that work. On August 16 SafePal notified all affected customers individually by email from security@safepal.com with the subject line "[Important] Your SafePal Order Information Has Been Affected." That same day a threat actor advertised a dataset on a cybercrime forum that cited the same order window and customer count; the listing was surfaced by DarkWebInformer and the seller offered to share order IDs and shipping countries so prospective buyers could check them against SafePal's verification tool.
What SafePal says it has done
- The company says the flaw has been fixed and additional security measures have been introduced.
- Retention of personal information in the relevant order‑processing environment has been cut to 90 days, subject to applicable legal requirements.
- Affected records have been purged from active servers, with a secured offline backup held solely to support potential investigations.
- SafePal said it is engaging an independent third‑party security firm to validate the fix and review order‑processing systems more broadly, and that it has contacted third‑party logistics and fulfillment partners to confirm the issue had not spread within their systems.
- Over 30 fraudulent websites and phishing links "tied to the scam activities" have been taken down; a status‑check page using an order ID number and shipping country was published and a dedicated support channel made available.
What this means for customers, logistics partners, and criminal actors
Customers: SafePal warned that because the records tie a named individual to a home address and a purchase, affected customers may face "fraudulent phone calls, emails, text messages, letters, refund offers, firmware‑update requests, fake customer‑support communications." The company said customers should not need to move assets solely because of the exposure, but that anyone who entered a seed phrase or private key in response to a suspicious message should treat that wallet as compromised.
Third‑party logistics and fulfillment partners: SafePal said it has contacted its logistics and fulfillment partners to confirm the issue had not spread into their systems and pointed to retention‑policy differences as material — noting Trezor credited a 90‑day data storage policy with limiting its own exposure after a separate disclosure three days earlier involving a shipping provider.
Criminal actors: A seller offered order IDs and shipping countries to let buyers verify records against SafePal's tool, and the listing was publicized on August 16. Chainalysis context cited by SafePal's notice highlights a pattern: Chainalysis counted 46 violent incidents documented globally through late June and more than $30 million stolen, noting a jump in French cases to 30 by mid‑2026 and reporting that only 12 of the 46 attempts produced a payment (26%), down from 49% in 2025.
SafePal has not reported any confirmed financial loss linked to the exposure. The company has asked customers who believe they suffered a loss to contact its support channel and said it is "contacting on‑chain asset‑tracing specialists on this incident." SafePal has not said that any loss has been traced to the exposed data. The company had not published a statement on its blog, incident page, or X account about the cybercrime‑forum listing as of writing, and it did not immediately respond to a request for comment.
How this episode resolves will hinge on whether buyers of the advertised dataset use the exposed records to escalate phishing, fraud, or physical threats, and on the results of the third‑party security validation and any investigative work tied to the secured offline backup. For now, SafePal's fixes, retention rollback to 90 days, and partner outreach are concrete steps — but the company itself has not tied any confirmed loss to the exposed order data.




