← Back to Home News · GLOBAL

SafePal Discloses Customer Data Breach After an Order Tracking Plugin Flaw

Make RegTech.com preferred on Google
SafePal Discloses Customer Data Breach After an Order Tracking Plugin Flaw
SafePal disclosed on 16 August 2026 that a flaw in an order tracking plugin exposed customer order information; it said no wallet keys, seed phrases or funds were affected.
AI Summary
  • SafePal has disclosed a customer data breach.
  • An authorisation flaw in the order tracking function of a third-party plugin exposed order information for roughly 39,798 customers, covering purchases made between March 2025 and April 2026.
  • The company stressed that no seed phrases, private keys, wallet passwords or funds were affected, but warned that the leaked contact and order details create a serious phishing and impersonation risk.

Crypto wallet maker SafePal disclosed a customer data breach, telling users on 16 August 2026 that unauthorised parties accessed a subset of customer order information. The company traced the incident to an authorisation flaw in the order-tracking function of a plugin used to process customer orders, which, under certain conditions, allowed order records to be read from the outside.

According to SafePal, the exposed data spans orders placed between 2 March 2025 and 11 April 2026 and affects roughly 39,798 customers. It is a familiar and uncomfortable pattern for the hardware wallet sector: the wallets themselves were held, but the customer database behind the online store was not.

What was exposed, and what was not

The information involved is order and contact data, not wallet credentials. SafePal says the exposed records could include a customer’s name, email address, shipping address, phone number and purchase details. Crucially, the company was emphatic that the breach “did not involve your seed phrase, private keys, wallet password, or other wallet credentials”, and added that it “never requests, collects, processes or stores such information from customers”. It said it found no evidence that the incident compromised access to SafePal wallets or funds.

A third party plugin, again

The root cause once again sits in the supply chain rather than the core product. The flaw was in a plugin bolted onto the order workflow, not in the wallet firmware or the app. That echoes the breach earlier disclosed by Trezor, whose customer data was exposed through its ShipMonk shipping partner, another hardware wallet maker undone not by its device but by a vendor sitting next to its order pipeline. And it lands amid sharply heightened breach activity: the SafePal disclosure follows hard on the heels of the Trezor incident and a wider run of data breaches across crypto and fintech in recent months, a cadence that has turned ordinary customer databases into one of the sector’s most reliably targeted assets. The sector keeps relearning a blunt lesson: a wallet vendor’s security perimeter is only as strong as the third-party tools that touch its customer data. It also contrasts with product-level failures such as the Coldcard firmware flaw, where the risk lived inside the device itself. Both routes end in the same place for the customer.

The real risk is targeted phishing

With names, addresses, phone numbers and specific purchase histories in circulation, the immediate danger is highly tailored fraud. SafePal warned that attackers may use the details for “fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests”, messages that look credible precisely because the sender appears to know what the customer bought and where it was shipped. The company said it had already taken down more than 30 fraudulent websites and phishing links.

What it means for compliance and security teams

For compliance, data-protection and security functions at wallet vendors and at any firm shipping physical products to crypto customers, the SafePal disclosure is a compact case study:

  • Third-party risk is your risk. Plugins, shipping partners and order-management tools inherit access to customers’ personal details; they belong inside vendor due diligence, access reviews and penetration testing, not outside them.
  • Practise data minimisation. Order systems that retain names, addresses, and phone numbers for a year or more widen the blast radius. Shorter retention and tighter access limit what a single flaw can expose.
  • Plan the phishing response, not just the fix. Closing the flaw is step one; the harder task is protecting customers from the follow-on impersonation wave, which is where SafePal’s takedowns and clear user guidance do their work.
  • Disclose early and plainly. A prompt notice that states what was and was not affected is itself a control, it lets customers recalibrate their trust before an attacker exploits the gap.

No keys were lost, and no funds moved, and SafePal deserves credit for a clear, prompt disclosure. But the episode is another reminder that in crypto the attack surface has widened well beyond the wallet. Increasingly the softest target is not the cryptography at all, but the ordinary customer database sitting behind the shop front. This recurring pattern of vendor and supply-chain failure is why our Voice column argues that hardware wallet failures demand statutory security standards rather than being left to voluntary best practice. You can read SafePal’s full security update for the company’s own account and its guidance to affected customers.

Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.