Industry News

SafePal Plugin Flaw Exposes Data of Nearly 40,000 Customers

The Currency Analytics · 18 Aug 2026
Key Takeaway Regularly audit and update any third-party plugins connected to your business systems, as these are common entry points for data breaches.

Crypto wallet provider SafePal confirmed on Saturday that a security flaw in one of its order tracking plugins allowed unauthorised third parties to access personal customer data. The company said nearly 40,000 customers were affected by the breach.

SafePal emphasised that the most sensitive wallet-related information — private keys and recovery phrases — was not exposed, meaning customer funds should remain secure. However, other personal data was accessible, raising concerns about potential follow-on scams such as phishing attempts targeting affected users.

This incident highlights a growing trend where attackers target third-party plugins and integrations rather than core systems, since these components often have weaker security controls. Businesses using similar plugins for order tracking, e-commerce, or customer management should review third-party software for known vulnerabilities.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Currency Analytics. We link back to every original so you can read it yourself.