Order tracking gap exposes SafePal buyers’ names and home addresses

SafePal says an authorization flaw in its order tracking plugin exposed the personal details of about 39,798 customers, but no wallet credentials.

CSBadmin
2 Min Read

A defect in SafePal’s order-tracking plugin laid bare the personal details of roughly 39,798 of the hardware wallet maker’s customers.

The authorization bug let an outsider view another customer’s order information under certain conditions. Names, email addresses, shipping addresses, phone numbers, and purchase details were exposed.

Wallet credentials stayed out of the breach. SafePal says seed phrases, private keys, wallet passwords, bank details, payment card numbers, and government-issued IDs were not exposed, and it has found no sign that wallets or funds were compromised.

Purchase records spanning March 2, 2025 to April 11, 2026 are involved. A scheduled data-cleanup process stopped working between September 2025 and April 2026 because of a configuration error, which is why older records remained in the environment.

The company said it first received a report consistent with the issue in early May 2026, treated it as an isolated case, then confirmed the root cause during a full review and rebuild of its order pipeline in July. Affected customers were emailed on August 16, and retention in the order-processing environment has been cut to 90 days.

A listing on a cybercrime forum is now peddling a dataset with the same order window and customer count. The company is telling buyers to view any out-of-the-blue contact that references a SafePal purchase, whether by phone, email, post, or in person, as suspicious.

The disclosure follows Trezor’s breach at logistics partner ShipMonk three days earlier, a reminder that hardware wallet vendors hold high-value targeting data.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.