Particle.news
Download on the App Store

SafePal Authorization Flaw Exposes Order Data of Nearly 40,000 Customers

The leak raises the risk of targeted phishing and physical attacks against hardware‑wallet owners.

Overview

  • SafePal disclosed on Sunday that an authorization bug in an order‑tracking plugin allowed unauthorized access to order records for about 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • Exposed fields include names, email addresses, phone numbers, shipping addresses and purchase details, while SafePal says seed phrases, private keys, wallet passwords, payment data and government IDs were not involved and there is no evidence wallets or funds were directly compromised.
  • SafePal says it first saw a phishing report in early May, launched a full review in July that found the plugin flaw, and discovered a separate configuration error that stopped a data‑cleanup routine from September 2025 through April 2026, which widened the window of retained records.
  • In response the company patched the vulnerability, removed affected records from active e‑commerce servers, emailed impacted customers, published a verification tool, took down more than 30 fraudulent sites, shortened retention to 90 days and hired an independent security firm to audit remediation, while a threat actor has claimed to be selling the data online (unverified).
  • The incident follows similar hardware‑wallet vendor exposures and raises a real risk that attackers will use proof of ownership plus home addresses to run convincing phishing, impersonation or physical 'wrench' attacks, so affected users should refuse any request for seed phrases and treat wallets as compromised only if those secrets were already shared.