Incident case file
Sign in to watchSafePal Order-Tracking Plugin Data Breach — 39,798 Customers Exposed
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatEarly May 2026 (per SafePal's account): First signal of the issue is received internally. Jul 2026: A full review of the matter is opened. Aug 16, 2026: SafePal publicly discloses the breach and individually notifies all 39,798 affected customers via email from security@safepal.com, subject line '[Important] Your SafePal Order Information Has Been Affected.' The company confirms the vulnerability has been patched, provides a verification tool allowing customers to check exposure status by order number and shipping country, and states that no wallet access, seed phrases, private keys, passwords, banking details, card numbers, or identity documents were part of the exposed dataset. SafePal explicitly separates this incident from a similar, contemporaneous disclosure at Trezor/ShipMonk, noting the reported mechanism there (a SQL injection in Metabase) differs from the order-tracking plugin flaw responsible for the SafePal exposure.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)