SafePal Data Exposure Hits Nearly 40,000 Customers Due to Order-Tracking Flaw
SafePal, a maker of cryptocurrency hardware wallets, has confirmed that an authorization flaw in a third-party order-tracking plug-in exposed sensitive customer data. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details for approximately 39,798 customers.
The company said it notified all affected customers individually via email on August 16, sent from security@safepal.com with the subject line '[Important] Your SafePal Order.' While SafePal has not indicated that financial credentials or wallet seed phrases were compromised, the exposed contact and shipping details could still be used by attackers for targeted phishing or scam attempts against customers.
This incident highlights a growing risk for businesses that rely on third-party plug-ins or integrations to manage orders and logistics. Even when core systems are secure, weaknesses in connected tools can create openings for data exposure, putting customer trust and compliance obligations at stake.