SafePal recently revealed that nearly 40,000 users had their order details exposed due to a technical vulnerability. The breach occurred between early 2025 and mid-2026, compromising personal contact and shipping information.

Advertisement

The 39,798 customers caught in the plug-in flaw

SafePal has confirmed that unauthorized parties gained access to the order information of approximately 39,798 customers.. According to the report, the security incident spanned a significant window of time, affecting users who placed orders between March 2, 2025, and April 11, 2026.

The root cause of the leak was not a failure of the wallet's encryption, but rather a flaw in an order-tracking plug-in. This suggests that while the core product remains secure, the peripheral e-commerce tools used by SafePal to manage customer logistics created a backdoor for external actors to scrape sensitive data.

From shipping addresses to phone numbers: The phishing threat

The compromised dataset is extensive, including customer names, email addresses, phone numbers, and shipping addresses, as well as specific purchase details. While SafePal noted that private keys, seed phrases , and the hardware wallets themselves remain secure, the exposure of this "last mile" data creates a high-risk environment for the affected users.

The primary danger now is targeted phishing. Because attackers know exactly when a user bought a SafePal device and where it was shipped, they can craft highly convinicng fraudulent emails or SMS messages. These messages may mimic official SafePal support, urging users to "verify" their device or "update" their firmware by clicking a malicious link, which could then be used to steal the very seed phrases that the company says are currently safe.

A recurring vulnerability in the 'last mile' of crypto hardware

This incident reflects a broader, systemic trend within the cryptocurrency hardware sector where the security of the device is often decoupled from the security of the storefront.. Many users treat the purchase of a hardware wallet as a security upgrade, yet the act of buying one often requires handing over a wealth of PII (Personally Identifiable Information) to a web-based shop that may rely on third-party plugins.

Historically, the industry has seen similar tensions where the "secure" nature of a cold storage device is undermined by the "insecure" nature of the shipping and logistics chain. When a provider like SafePal experiences a leak of this scale, it underscores the reality that the threat model for a crypto user begins at the checkout page, not just at the moment they generate their recovery phrase.

Who exploited the order-tracking vulnerability?

Despite the disclosure, several critical details remain missing from the report. It is currently unknown who the "unauthorised parties" are or whether the data has already been listed for sale on dark-web forums. Furthermore, SafePal has not specified if the flawed order-tracking plug-in was a proprietary tool developed in-house or a third-party service provided by an external vendor.

There is also no information regarding whether SafePal has offered identity theft monitoring or other remediation services to the 39,798 impacted individuals. Until the company clarifies the origin of the plug-in and the identity of the attackers,users are left to rely solely on their own vigilance against unsolicited communications.