Order Tracking Vulnerability in SafePal: Data of 39,798 Customers Exposed, Wallets Secure
SafePal announced that the personal and order data of 39,798 customers were affected due to an authorization vulnerability in its order tracking plugin, while reporting that wallet information and funds remain secure.
According to crypto wallet provider SafePal, the issue stemmed from an authorization error in the order tracking plugin used to track the status of orders. The error allowed unauthorized individuals to access order information belonging to certain customers. The incident involved users who placed orders between March 2, 2025, and April 11, 2026.
The company stated that the names, email addresses, delivery addresses, phone numbers, and purchase details of approximately 39,798 customers were exposed. In contrast, seed phrases (recovery words), private keys, wallet passwords, payment information, and government-issued ID numbers were not affected. SafePal announced that there is no evidence of wallet access or customer funds being compromised.
SafePal notified affected customers via email
SafePal announced that it has resolved the vulnerability and implemented additional security measures. The company has sent individual emails to all affected customers. Users can check whether they are affected via the web page published by SafePal for status checks.

Users need to remain vigilant against potential phishing and impersonation attempts. Affected users should use official channels instead of links in suspicious messages, renew their wallet passwords, and never share their seed phrase, private key, or password with anyone.