SafePal revealed on Aug. 16, 2026, that an authorization flaw in its order-tracking plugin exposed customer order information belonging to approximately 39,798 users.
The exposed records covered orders placed between March 2, 2025, and April 11, 2026, and included names, email addresses, shipping addresses, phone numbers and detailed purchase information. According to the non-custodial wallet provider, seed phrases, private keys, wallet passwords, payment card numbers, bank account details and government-issued identification numbers were not exposed.
SafePal first received a phishing report in early May, initially treating it as isolated before launching a formal security investigation. In July, the company began a full review and rebuild of its order-processing pipeline and confirmed the plugin defect. A separate data-retention failure between September 2025 and April 2026 left older order records stored longer than intended, widening the affected range back to March 2025.
Affected customers were notified individually by email, and SafePal launched a tool for buyers to check orders using their order number and shipping country. The company has removed more than 30 phishing websites, shortened personal data retention to 90 days, and is engaging an independent third-party security firm to validate the fix. SafePal stressed that users do not need to move assets solely because order information was exposed, but anyone who entered a seed phrase or private key into a suspicious site should treat the wallet as compromised and transfer remaining assets.