What happened (in plain human words)
Hardware-wallet maker SafePal recently confirmed that customer order records were siphoned off after someone exploited an order-tracking flaw in a plugin used by their online store. The company says the exposure covers orders placed between March 2, 2025 and April 11, 2026 — affecting roughly 39,798 customers.
The stolen details include names, email addresses, shipping addresses, phone numbers, and what people bought. Importantly, SafePal says there’s no sign that private wallet secrets were taken — things like seed phrases, private keys, payment card numbers, bank details, or passwords were not involved in the leak. They also say there’s no evidence this incident gave attackers access to actual SafePal wallets or funds.
After spotting odd activity, SafePal escalated the matter, fixed the plugin vulnerability, and started a full review of their order-processing system. They also found a separate configuration error that caused some old order data to stick around longer than it should have, stretching retained records back to March 2025.
SafePal emailed people they believe were affected on August 16 and set up an online verification tool where customers can check if a particular order number was impacted. The company says it purged exposed personal data from active e-commerce servers but is keeping a single encrypted offline copy for potential law-enforcement needs.
Why this matters and what to do (do it now, not later)
Leaked order records are a goldmine for social engineers: expect targeted phishing emails, convincing phone calls pretending to be support, fake firmware-update notices, bogus returns or refund schemes, and other trust-abuse tricks. Some customers already reported phishing attempts and suspicious calls as early as May.
If your order was in the affected window, here’s a quick, slightly paranoid checklist:
- Do not click links or install firmware from unsolicited emails or messages. If SafePal contacts you, verify via their official site or your account dashboard — not a link in an email.
- Never share your seed phrase, private key, or any secret with anyone. No legitimate support rep will ever ask for them.
- Be extra skeptical of calls claiming urgent action (firmware updates, refunds, legal issues). Hang up and call back via an official number from the company website.
- If you already gave your seed phrase or private key to someone, assume that wallet is compromised. Move funds to a new wallet created on a trusted device or the official app immediately.
- Watch your inbox for phishing attempts and set up two-factor authentication where possible.
SafePal also reported taking down dozens of fraudulent sites and phishing links tied to this incident and is working with a third-party security firm to validate their fixes. If you’re unsure whether you’re affected, use the verification option the company published or contact their support through official channels.
Short version: your delivery address and contact info might be out there, which sucks, but your wallet’s secret sauce probably isn’t — unless you gave it away after getting fooled. Keep your seed phrases private, double-check any strange messages, and move funds only if you suspect the wallet itself was compromised.