Threat Intelligence

SafePal Data Exposure Hits Nearly 40,000 Customers Due to Order-Tracking Flaw

The Hacker News · 18 Aug 2026
Key Takeaway Regularly audit third-party plug-ins and integrations connected to your business systems, as vulnerabilities in these tools can expose customer data even when your core platform is secure.

SafePal, a maker of cryptocurrency hardware wallets, has confirmed that an authorization flaw in a third-party order-tracking plug-in exposed sensitive customer data. The exposed information included names, email addresses, shipping addresses, phone numbers, and purchase details for approximately 39,798 customers.

The company said it notified all affected customers individually via email on August 16, sent from security@safepal.com with the subject line '[Important] Your SafePal Order.' While SafePal has not indicated that financial credentials or wallet seed phrases were compromised, the exposed contact and shipping details could still be used by attackers for targeted phishing or scam attempts against customers.

This incident highlights a growing risk for businesses that rely on third-party plug-ins or integrations to manage orders and logistics. Even when core systems are secure, weaknesses in connected tools can create openings for data exposure, putting customer trust and compliance obligations at stake.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.