SafePal disclosed on 16 August 2026 that an authorization flaw in an order-tracking plug-in let outsiders access personal order records for about 39,798 customers, while seed phrases, private keys, and wallet funds were not part of the leak.

What was exposed

In its official security update, the hardware-wallet maker said customers who ordered between 2 March 2025 and 11 April 2026 had order data accessed externally. The fields named in the advisory are names, email addresses, shipping addresses, phone numbers, and purchase details.

What was not in the dump, per SafePal: seed phrases, private keys, wallet passwords or credentials, bank account numbers, payment card numbers, or government IDs. The company says it never collects seed phrases or private keys, and that it found no evidence the incident itself opened access to SafePal wallets or balances.

CoinDesk and BleepingComputer independently reported the same numbers and scope on the day of the disclosure. BleepingComputer also notes a threat actor claiming to sell a matching dataset on a cybercrime forum; the outlet says it has not independently verified that the seller holds the stolen file.

How the flaw worked

SafePal describes the bug as an authorization flaw in a plug-in tied to customer order tracking. Under certain conditions, it allowed one party to pull another customer’s order record (the same class of IDOR-style storefront bug that lets someone change an order ID and read a stranger’s receipt).

Timeline from the company and BleepingComputer’s write-up:

  • Early May 2026: SafePal received a report consistent with the issue and first treated it as isolated, while adding protections and starting a formal investigation.
  • May onwards: Customers reported phishing emails and calls that referenced SafePal hardware (including fake “firmware update” pitches). SafePal says it is unclear whether every early report ties to this exact flaw.
  • July 2026: During a full review and rebuild of the order-processing stack, engineers found the plug-in authorization bug.
  • Investigation later confirmed a threat actor had used the flaw to steal the ~39,798 records.
  • A separate configuration error had also broken a data-cleanup job between September 2025 and April 2026, so some order data sat longer than intended (back to March 2025).

That last detail matters for scale: the leak window is as wide as the retention failure, not only the day the bug was found.

What SafePal says it has done

Per the security advisory:

  • Fixed the plug-in issue and added extra controls.
  • Engaged an independent third-party security firm to validate the fix and review order-processing systems.
  • Shortened personal-data retention in the relevant order environment to 90 days (legal holds aside).
  • Purged personal data for affected orders from active e-commerce servers, while keeping an encrypted offline copy for possible law-enforcement work.
  • Emailed affected customers on 16 August from security@safepal.com with subject "[Important] Your SafePal Order Information Has Been Affected".
  • Opened a dedicated support channel and a scam-protection / status check page (order number + shipping country).
  • Took down more than 30 phishing sites and links tied to the incident, with monitoring continuing.
  • Contacted logistics and fulfillment partners to check for lateral spread.

Why order data is still dangerous

Hardware wallets are sold as offline key storage. This incident did not break the chip model SafePal advertises. It broke the web store that ships the boxes.

Names, phones, emails, and home addresses are enough for high-quality social engineering. An attacker who knows you bought a specific model can invent a firmware update, a return, a refund, a “legal notice,” or a courier call that names your real order. That is the risk SafePal, CoinDesk, and BleepingComputer all put first.

The pattern is familiar to anyone who already follows self-custody hygiene: the chain and the device can be fine while the human channel (email, WhatsApp, SMS, door knock) is where the seed leaves the house. Readers who want a full checklist on fake support and lookalike downloads can use our phishing and fake-wallet guide; the short version for this breach is below.

What affected buyers should do

SafePal’s own guidance for affected buyers:

  1. Check status. Use the official verification tool on safepal.com (type the domain yourself; do not follow email links). Confirm whether your order fell in the March 2025–April 2026 window.
  2. Treat unexpected contact as hostile. Firmware “urgent updates,” refund offers, support that messaged you first, and phone numbers that already know your shipping address are classic follow-on attacks.
  3. Never share seed phrases or private keys. SafePal says it will not ask for them. If you already typed a seed or key into a form, chat, or call, treat that wallet as burned: create a new wallet on a trusted official device or app, move remaining funds, then contact official support from a typed URL.
  4. You do not need to replace hardware or move coins solely because order data leaked, according to SafePal, if you never handed over credentials.
  5. Report phishing. Use the company’s dedicated channel so domains can be taken down.

For LatAm buyers who ordered hardware through the same shop (or any global e-commerce wallet vendor), the practical lesson is the same as for a courier scam in Mexico City or São Paulo: the person who already has your address and order ID is more convincing than a random spam blast. Slow down, open the real site from a bookmark, and hang up on unsolicited “security” calls.

Takeaway

On 16 August 2026, SafePal confirmed that roughly 39,798 hardware-wallet order records were accessed through a storefront tracking plug-in, and that seeds, keys, and funds were outside the leak. The live threat is phishing built on real names and shipping details, not a remote drain of sealed devices.

If you bought a SafePal product in that date range, verify on the official site, harden your email and phone filters, and treat any firmware or refund outreach as a scam until you prove otherwise from a domain you typed yourself.