Overview
- SafePal disclosed Sunday that an authorization flaw in an order-tracking plug-in allowed access to names, shipping addresses, contact details and purchase specifics for 39,798 orders placed between March 2, 2025 and April 11, 2026.
- The firm says private keys, seed phrases, payment card numbers, government IDs and customer funds were not exposed and found no evidence the incident breached wallet security.
- SafePal patched the plug-in, notified affected customers by email from security@safepal.com, removed more than 30 phishing sites tied to the leak and opened a support channel and an online verification tool for buyers.
- The main ongoing danger is targeted phishing and impersonation using real order details, so users should ignore unsolicited requests for seed phrases and treat any site asking for recovery data as a compromise.
- The episode underlines a broader industry pattern where peripheral systems—order processing, web plugins and third-party services—create attack paths even when hardware-wallet cryptography remains intact, echoing past Ledger and Coldcard incidents.