WARSAW, August 17, 2026, 08:16 CEST
- SafePal says an order-tracking flaw exposed data for about 39,798 customers.
- Names, contact details, shipping addresses and purchase records were accessed.
- Wallet keys and funds were not exposed, but targeted phishing risk has increased.
SafePal disclosed that an authorization flaw exposed order information for about 39,798 customers. The crypto-wallet provider says the incident did not compromise wallet credentials or funds.
The distinction matters. Attackers gained data that can identify hardware-wallet owners, their addresses and purchases. That creates a narrow, credible path for tailored scams.
SafePal published the disclosure on Sunday and notified affected customers separately. Reuters independently reported the incident the same day.
| Incident measure | Verified detail | Status on August 17 |
|---|---|---|
| Affected customers | Approximately 39,798 | Individually notified |
| Orders in affected range | March 2, 2025 to April 11, 2026 | Historical exposure window |
| Initial warning signal | Report consistent with the issue in early May 2026 | Escalated into a formal investigation |
| Root-cause work | Order-processing review and rebuild began in July | Authorization flaw identified and fixed |
| Fraud infrastructure removed | More than 30 websites and phishing links | Monitoring continues |
| New retention period | 90 days, subject to legal requirements | Introduced after the incident |
The flaw sat in an order-tracking plug-in. Under certain conditions, it let an unauthorized party access another customer’s order record. SafePal says it fixed the defect and strengthened access controls.
“Your hardware wallets, private keys, seed phrases, and crypto assets are safe and unaffected,” SafePal says. It found no evidence that the incident itself opened wallets or funds. SafePal phishing alert and FAQ
| System or data layer | What SafePal says was accessed | What SafePal says was not accessed | Practical implication |
|---|---|---|---|
| E-commerce order tracking | Name, email, shipping address, phone number and purchase details | Payment-card and bank-account information | Attackers can construct convincing order-related messages |
| Hardware wallet and cold storage | No access identified | Seed phrases, private keys and wallet passwords | The device does not need replacement solely because of this incident |
| Identity records | Contact and delivery data | Government-issued identification numbers | Impersonation risk remains despite narrower data exposure |
| Wallet funds | No evidence of access | Crypto assets through the incident itself | Loss becomes possible if a victim later gives credentials to a scammer |
The exposed data can make a fake refund, support call or firmware notice look authentic. SafePal also warns about malicious letters, QR codes and unexpected hardware deliveries.
The investigation found a separate retention problem. A scheduled cleanup stopped working correctly between September 2025 and April 2026. SafePal says that error did not cause access, but kept older records available longer.
SafePal shortened relevant data retention to 90 days. It is engaging an independent security firm to validate the fix and review its order-processing systems. No audit result has yet been published.
| User situation | Recommended response | Why it matters |
|---|---|---|
| Received the official affected-customer email | Verify status through SafePal’s manually typed web address | Avoids links embedded in copied or forged notices |
| Received an unsolicited link or QR code | Do not open or scan it; report the sender | Blocks common credential-harvesting routes |
| Received a purported SafePal phone call | Hang up, record details and block the number | SafePal says employees do not initiate customer calls |
| Still controls all wallet credentials | Do not move assets solely because order data was exposed | The incident did not reach keys or wallet systems |
| Entered a seed phrase or private key after suspicious contact | Create a trusted new wallet and move remaining assets immediately | The old wallet must be treated as compromised |
Affected customers were emailed from [email protected] on August 16. SafePal says the subject begins with “Important” and states that order information was affected. Users should still type the company address manually.
The company says official support will never request a recovery phrase, PIN or private key. It also says genuine staff will not demand an urgent firmware upgrade through a link.
Risks: SafePal’s conclusions remain company-reported, and the independent review is unfinished. Further affected records, partner exposure or financial losses could emerge as investigations continue.
The immediate danger is social engineering, not a broken cold wallet. Buyers should distrust any contact that proves knowledge of their order, then asks for a secret.
Further analysis
Who was affected by the SafePal incident?
How can a customer check whether their data was exposed?
[email protected] on August 16. Customers can also check with their order number and shipping country. They should type SafePal’s address manually instead of following an unexpected link.