SafePal Discloses Authorization Flaw Exposing Order Data of 39,798 Customers
Image: Sahifa Sabq al-Ilktruniya

Crypto · 16 August, 2026 · 2 min read

SafePal Discloses Authorization Flaw Exposing Order Data of 39,798 Customers

Happened

Authorization flaw exposed order data for about 39,798 SafePal customers. Personal data exposed: names, addresses, emails, phones, and purchase details; keys/seeds remained safe.

Split on

Whether the timeline of discovery and escalation is emphasised.

Left out

2 of 3 outlets skipped it: seed-phrase phishing risk could include public-forum resale or diffusion.

16outlets compared

@coindeskAfrica For PressBigGo FinancebloomingbitCrypto NewsCryptopolitanDiarioBitcoinForkLog

Same story, two versions

tap a side to read it in full

Startup FortuneStartup Fortune

That's more than three months between the first warning sign and the moment customers found out
Read the original

The Business TimesThe Business Times

An authorisation flaw in the order tracking system allowed access
Read the original
VS

Startup Fortune stresses slow escalation; The Business Times focuses on the technical cause.

SafePal breach details

SafePal disclosed a data breach affecting about 39,798 customers after an authorization flaw in its order-tracking system allowed unauthorized access to order information tied to customers’ purchases.

between Mar 2, 2025, and Apr 11, 2026

The Business TimesThe Business Times

The company said the affected orders were placed between Mar 2, 2025, and Apr 11, 2026, and that the exposed records included names, email addresses, shipping addresses, phone numbers and purchase histories.

Image from @coindesk
@coindesk@coindesk

SafePal said the breach did not involve access to “seed phrases”, private keys, wallet passwords, bank account information, payment card numbers or government-issued identification numbers, and it said it found no evidence of unauthorized wallet access or asset theft.

In response, SafePal said it fixed the issue and introduced further security measures, including reducing personal-data retention in its order-processing system to 90 days.

Phishing risk and warnings

SafePal warned that exposed order details could be used for targeted phishing and impersonation attempts, with attackers armed with genuine names, addresses and purchase details to craft more convincing fraudulent communications.

The company said attackers may impersonate SafePal employees and try to steal wallet credentials by using firmware updates, refunds or replacement devices as a pretext.

Image from Africa For Press
Africa For PressAfrica For Press

SafePal also told customers to treat unexpected contact as suspicious, and it warned: "Consider suspicious any contact unexpected or hardware delivery that references your SafePal purchase".

Bloomingbit reported that SafePal disclosed the authentication flaw on X and that it had not immediately responded to The Block’s emailed questions about the timing of the flaw’s introduction or how many attackers obtained the data.

What SafePal says comes next

SafePal said it has identified and taken down more than 30 fraudulent websites and phishing links tied to the breach, and it said it emailed affected customers individually on Sunday.

SafePal has now reduced personal-data retention in the relevant order-processing environment to 90 days

Crypto NewsCrypto News

The company said it is engaging an independent third-party security firm to validate its fix and conduct a broader review of its order-processing systems, and it said the firm has not yet been named publicly.

SafePal also said affected customers’ personal information has been removed from active e-commerce servers while an encrypted offline copy is being retained to support potential investigations.

In addition to tightening retention to 90 days, SafePal said it launched a verification tool allowing buyers to check whether their orders were affected using their order number and shipping country.