SafePal is warning customers of a SafePal data breach affecting approximately 39,798 people, after an authorisation flaw in its order-tracking system was exploited to lift customer order information, and a threat actor is now shopping the stolen records on a cybercrime forum.

The exposed data includes names, email addresses, shipping addresses, phone numbers and purchase information for orders placed between 2 March 2025 and 11 April 2026. Crucially, the company says wallet seed phrases, private keys, passwords, bank account information, payment card numbers and government-issued identification numbers were not part of what was taken. ‘No evidence has been found that the incident itself compromised access to SafePal wallets or funds,’ the company said in a security advisory published on Sunday.

How the SafePal Data Breach Unfolded

SafePal says it first received a report consistent with the incident in early May 2026, initially treating it as an isolated case. A customer had posted on X around that time to report receiving both a SafePal phishing email and a phone call from someone claiming to be a company employee. The phishing email alleged a security vulnerability in the SafePal X1 hardware wallet and urged the recipient to install a firmware update.

The company escalated to a formal security investigation and introduced additional protections. ‘As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations,’ the advisory reads.

In July, SafePal undertook what it described as a ‘full review and rebuild’ of its order-processing system. That work uncovered an authorisation flaw in the order-tracking function of a plug-in, which had allowed unauthorised access to other customers’ order information. The company says it has since fixed the vulnerability and implemented additional security measures, and is working with a third-party security firm to validate the fix and conduct a broader review of its order-processing systems.

The investigation also turned up a separate problem: a configuration error had caused a data-cleanup process to stop functioning correctly between September 2025 and April 2026, meaning order data had been retained as far back as March 2025. SafePal says it has now purged personal data from active e-commerce servers, though it is retaining an encrypted offline copy for potential law-enforcement purposes.

Stolen Records Now Listed on a Cybercrime Forum

As spotted by DarkWebInformer, a threat actor has listed the stolen SafePal customer data for sale on a cybercrime forum. The seller referenced the same affected order period and the same figure of approximately 39,798 customers that SafePal disclosed. To prove the sale is legitimate, the threat actor is offering to share order ID and shipping country details from stolen orders, information that can be cross-checked against SafePal’s own online verification tool.

The forum post is blunt about pricing expectations: ‘Not interested in low balls, please come correct and with a good price or do not message me at all.’ BleepingComputer, which reported on the forum listing, has not independently verified that the threat actor actually holds the stolen data.

SafePal notified all affected customers by email on 16 August, with the subject line ‘[Important] Your SafePal Order Information Has Been Affected.’ The company has also launched an online verification tool that lets customers enter their order number and shipping country to check whether their specific order details were among those stolen.

What Affected Customers Should Do Now

The phishing activity linked to this incident began well before the public disclosure. Customers reported SafePal phishing emails and phone calls as early as May, and SafePal says it has already taken down more than 30 fraudulent websites and phishing links tied to the breach. The company is warning customers to stay alert to targeted phishing attempts involving firmware upgrades, product returns, refunds or legal investigations.

For the vast majority of those affected, the practical advice is straightforward: there is no need to replace a hardware wallet or move cryptocurrency as a result of the breach itself. The stolen data is shipping and contact information, not cryptographic credentials.

The exception is anyone who has already responded to a phishing message and shared their seed phrase or private key. SafePal says those customers should treat their wallet as compromised and transfer any assets to a new wallet on a trusted SafePal device or official application without delay. An order-tracking plug-in flaw is a relatively contained problem; handing over a seed phrase is not.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version