SafePal said an access-control flaw exposed order information tied to about 39,798 customers, affecting purchases made between March 2 and April 11 this year. The company said the exposed data included names, contact details, shipping addresses and purchase information.
According to SafePal, the incident did not expose seed phrases, private keys, wallet passwords or customer funds. The company said it does not request or store those wallet credentials.
What the company says happened
SafePal said the weakness could, under certain conditions, allow an unauthorized person to view another customer’s order information. The company described the problem as an access-control issue rather than a compromise of wallet secrets or account funds.
The affected records were limited to order-related personal information. SafePal said seed phrases, private keys, wallet passwords and other wallet credentials were not involved in the breach.
Window of exposure and customer impact
The company said the incident affected orders placed from March 2 through April 11. In total, around 39,798 customers had data exposed, based on SafePal’s disclosure.
While the company said no wallet credentials were exposed, the leaked order details could still be valuable to attackers because they can be used to make outreach appear genuine. That risk has become a central part of SafePal’s warning to affected users.
Phishing concerns after the leak
SafePal said scammers may try to use the stolen order details in phishing campaigns that look legitimate. The company specifically warned about spoofed calls, phishing emails and text messages, as well as fake refund offers and links to malicious websites.
The company advised customers not to transfer cryptocurrency solely because their order data was exposed. It also said any unexpected contact that references SafePal should be treated as suspicious.
Fixes, review and data-retention changes
SafePal said it has fixed the flaw and added extra security controls. It also said email notifications were sent to customers considered at risk.
As a next step, the company is hiring an independent cybersecurity firm to verify the fix. SafePal also said external partners are involved in the investigation and that it is limiting retention of personal order data to 90 days after the flaw was fixed.
Source: Cryptopolitan