Plugin flaw exposed data of 39,798 Safepal customers

An order-tracking plugin flaw let unauthorized actors access names, emails, phone numbers and shipping addresses for 39,798 Safepal customers from March 2, 2025, to April 11, 2026.

Safepal, a Seychelles-based hardware wallet maker, disclosed that a flaw in an order-tracking plugin allowed unauthorized actors to access personal information for 39,798 customers between March 2, 2025, and April 11, 2026. Exposed data included names, email addresses, phone numbers, shipping addresses and purchase details.

The company confirmed that seed phrases, private keys and wallet passwords were not accessed in the incident.

Safepal traced the exposure to a malfunctioning plugin used to track orders. The company said it removed the affected plugin, applied a patch, shortened its data retention period to 90 days and took down 30 fraudulent websites linked to scam operations.

The records cover customer orders placed during the 13-month window and include contact and delivery information tied to those purchases.

Safepal warned that the exposed details could be used for targeted phishing and social-engineering attacks, including fraudulent phone calls, texts and emails, refund offers, fake firmware-update prompts, counterfeit customer-support messages and malicious websites aimed at extracting wallet credentials or further personal data.

Security researcher Tay highlighted that the presence of shipping addresses raises the risk of physical robberies and so-called wrench attacks, in which criminals coerce victims to surrender keys. Tay also pointed to reports of suspicious messages and contacts in spring and summer that may be linked to the dataset.

Another investigator, Specter, reported that the company had received phishing reports as early as April and that the public disclosure came later, a timing that drew criticism from some users. One customer who believes their information was included said Safepal deleted their data before the company announced the incident and criticized prior retention practices.

The Safepal incident follows a breach last year involving a shipping provider for another hardware wallet maker that exposed the contact and shipping details of 11,742 customers across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Both incidents involved third-party services that handled order and shipping data.

Safepal urged affected users to be vigilant, ignore unsolicited firmware updates and refund offers, and to verify customer-support channels through the company’s official website.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author