← Radar

Incident case file

Sign in to watch

SafePal Order-Tracking Plugin Data Breach — 39,798 Customers Exposed

Incident date 2026-08-15Last updated Aug 26, 2026

1 views

ResolvedNot applicable (Web2 e-commerceorder-tracking system; SafePal is a hardwaresoftware wallet provider)Third-party data breach — authorization flaw in an order-tracking plugin (no wallet or fund compromise)Cluster: SAFEPAL-DATA-2026-08

Estimated loss

$0

Victims identified

39798
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

Not publicly disclosed. A threat actor is reported to have resold the exposed order data.

Funds moved to

Not applicable. SafePal explicitly states no evidence was found that the incident compromised access to SafePal wallets or funds; seed phrases, private keys, wallet passwords, and payment/banking data were not part of the exposed dataset.

Linked

An authorization flaw in a third-party order-tracking plugin allowed unauthorized viewing of other customers' order records, covering orders placed between 2 March 2025 and 11 April 2026. Exposed data: customer names, emails, phone numbers, shipping addresses, and purchase details. The primary downstream risk is physical/social-engineering targeting of known hardware-wallet owners (fake support requests, seed-phrase phishing, spoofed firmware updates) rather than direct on-chain theft.

Chronology

1 beat
  1. Early May 2026 (per SafePal's account): First signal of the issue is received internally. Jul 2026: A full review of the matter is opened. Aug 16, 2026: SafePal publicly discloses the breach and individually notifies all 39,798 affected customers via email from security@safepal.com, subject line '[Important] Your SafePal Order Information Has Been Affected.' The company confirms the vulnerability has been patched, provides a verification tool allowing customers to check exposure status by order number and shipping country, and states that no wallet access, seed phrases, private keys, passwords, banking details, card numbers, or identity documents were part of the exposed dataset. SafePal explicitly separates this incident from a similar, contemporaneous disclosure at Trezor/ShipMonk, noting the reported mechanism there (a SQL injection in Metabase) differs from the order-tracking plugin flaw responsible for the SafePal exposure.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)