- A compromise in Safepal’s order-tracking plug-in leaked the sensitive data of almost 40,000 customers.
- The company assured that the incident didn’t reveal users’ wallet credentials, but it does expose them to targeted phishing attempts.
Following Trezor’s disclosure of a data leak affecting more than 13,600 customers across seven countries due to a compromise in its shipping service provider, another hardware wallet manufacturer warned users of a similar issue. Safepal, a non-custodial crypto wallet suite backed by Binance, reported a security incident exposing the sensitive information of 39,798 users.
The Safepal Data Leak
Safepal explained that an “authorization flaw in the order-tracking function for a plug-in associated with customer order information” led to the massive data leak. It didn’t name the compromised tool, but it revealed that the fault allowed customers to view each other’s order information. It opened unauthorized access to their names, contact numbers, email addresses, receiving addresses, purchase dates, and other personal details.
Additionally, the company stated that the plug-in exploit affects orders placed between March 2, 2025 and April 11, 2026. The dates coincided with a recurring complaint from buyers, who claimed they have been subject to numerous phishing attempts by people identifying themselves as Safepal representatives.
Increased Safepal Phishing Attempts
In most cases, the malicious actors have urged users to update their hardware wallets to supposedly patch up a firmware-level security vulnerability. It wasn’t clear how many fell for the scam, but individuals who received the call recounted how the person on the other line sounded too convincing, especially given the fact that the caller had specific details about their product purchases with Safepal.
Despite that, Safepal assured the public that the incident didn’t reveal users’ seed phrases, private keys, wallet passwords, and other wallet credentials since it does not need to collect, record, or process such crucial customer information. Hence, it advised them not to provide the same details to any person, even those claiming to be from the company.
Safepal admitted that the problem indeed exposed affected customers to targeted phishing and impersonation attempts. With that, it urged them to remain vigilant and not to entertain calls, emails, letters, text messages, refund offers, firmware update requests, or any communication requesting their wallet credentials or additional personal information.
Issue Patched
Safepal assured customers that it had already fixed the issue and enhanced its security measures upon discovery of the incident. It has also secured the services of an independent third-party entity to conduct security audits in its system as an extra measure and to detect any other unforeseen vulnerabilities.
Furthermore, the company said it now imposes a tighter retention period for customer orders to 90 days and has taken down more than 30 websites associated with Safepal impersonators.







