Key Takeaways:
- About 39,798 customers’ private and buy data had been disclosed through a flaw in an order monitoring plugin, in accordance with SafePal.
- The incident affected orders positioned between March 2, 2025, and April 11, 2026.
- Whereas no seed phrases, non-public keys, pockets passwords, cost knowledge and authorities IDs have been leaked, customers are at a larger threat of being phished, says SafePal.
SafePal has introduced a safety breach with buyer knowledge associated to bought on-line orders, creating new phishing considerations for crypto customers.
Expensive neighborhood,
Whereas your SafePal pockets, seed phrase, and personal keys are safe; we recognized a flaw within the order-tracking plug-in that led to unauthorized entry to data of a subset of consumers.
The difficulty has been fastened with extra safety measures…
— SafePal – Crypto Pockets (@SafePal) August 16, 2026
The corporate has said that it didn’t have its pockets infrastructure breached and that there is no such thing as a private knowledge that offers customers direct entry to their cryptocurrency property.

Order-Monitoring Flaw Uncovered Buyer Knowledge
SafePal states it occurred due to a bug in an ordering monitoring plugin for its ecommerce platform. This was as a result of that part of consumers was ready to entry the data, because of the vulnerability.
Round 39,798 shoppers may need been impacted from March 2, 2025, to April 11, 2026.
The leaked data included prospects names, e-mail tackle, delivery tackle, cellphone numbers, and buy data. SafePal said that it has reached out to affected customers one after the other by means of e-mail.
The corporate has moreover delivered a web page on-line the place shoppers can look at if their particulars had been included within the order by coming into their Order ID and nation of delivery.
Learn Extra: Trezor Data Breach Exposes 13,689 Users, Crypto Wallets Remain Safe From Attack
Crypto Wallets and Non-public Keys Had been Not Uncovered
Seed Phrases Stay Exterior the Breach
SafePal emphasised that it was not a seed phrase, non-public keys or pockets password leak. Particulars of financial institution accounts and cost playing cards or authorities identification had been additionally not compromised, the corporate mentioned.
These variations rely an incredible deal for crypto customers. The non-public data on an order doesn’t set up proof of identification or credentials to take management of the cost funds in a SafePal pockets.
Subsequently, SafePal suggested prospects to pay extra consideration to phishing and impersonation actions, slightly than speeding to switch their property.
Scammers could use legit names, addresses and shopping for particulars to forge legit messages. If not prospects, attackers can faux to be SafePal employees or prospects’ supply firms, and even Pacific assist staff, and ask prospects to reveal pockets particulars.
Learn Extra: Binance Blocks 11 Crypto Platforms in Major Compliance Move Affecting User Funds
SafePal Provides Safety Measures
SafePal claims that this vulnerability has already been patched and additional safety measures have been added.
The corporate additionally reminds the customers to be vigilant about unsolicited messages, emails and web sites. Prospects ought to by no means present their seed phrase, non-public key or pockets password to anybody, even when the request seems to return from SafePal assist.
SafePal has launched a particular scam-protection web page for the hit prospects and can be releasing extra data through its safety channels.
The incident demonstrates a reoccurring vulnerability confronted by hardware-wallet customers: swept traces of buyer knowledge can present researchers with a trick of what can basically be a extremely focused assault.

