Incident Overview: Plugin Flaw Leads to Data Exposure

Hardware wallet provider SafePal has issued a security advisory confirming a now-patched vulnerability in its official order tracking plugin. This flaw allowed unauthorized access to order-related information for a subset of its users during a specific period.

Scope of Impact and Data Compromised

The incident affected approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The information accessed primarily included:

  • Personal Identifiable Information: User names, email addresses, shipping addresses, and phone numbers.
  • Order Details: Specifics of the purchased products.

SafePal specifically emphasized that users' core cryptographic asset credentials remained secure and were not impacted. This includes:

  • Wallet seed phrases, private keys, and wallet passwords
  • Bank account information and payment card numbers
  • Any government-issued identification documents

Official Response and User Verification Steps

Technical Remediation

Upon discovering the vulnerability, SafePal's technical team immediately implemented a fix and deployed additional security measures to prevent similar incidents.

How to Check If You Are Affected

All identified affected users have been individually notified via their registered email addresses. For user verification, SafePal has launched an official checking portal. Users can enter their order number and shipping country to see if their data was involved.

Recommendations and Security Reminders

While asset keys were not exposed, SafePal apologized for the incident and issued critical reminders for all users:

  • Never share your wallet recovery phrase, private keys, or passwords with anyone. Legitimate staff will never ask for this information via email, SMS, or call.
  • Remain vigilant against potential phishing attempts or scams impersonating official channels that may follow this disclosure. Always verify the source of communications.

SafePal has committed to providing ongoing updates regarding the situation through its official blog. Users should refer to these channels for authoritative information when dealing with any communications related to this event.