Cryptocurrency hardware wallet provider SafePal has confirmed a significant data breach affecting 39,798 customers after attackers exploited a SafePal order-tracking vulnerability in its web store. The breach exposed sensitive customer personal identifiable information (PII) and shipping records for orders placed between March 2, 2025, and April 11, 2026. While private keys and wallet seed phrases were not compromised, the leaked customer data has made its way to dark web forums, where a threat actor is actively selling the database. SafePal began notifying impacted customers on August 16, warning users to remain vigilant against ongoing social engineering and phishing attacks.
How the Order-Tracking Vulnerability Was Exploited
The root cause of the breach stems from an authorization flaw—specifically an Insecure Direct Object Reference (IDOR), or Broken Object Level Authorization (BOLA)—within an e-commerce plug-in integrated into SafePal’s order-processing platform. In BOLA/IDOR scenarios, an application endpoint fails to properly validate whether the requesting user is authorized to view a specific resource. By manipulating parameter values—such as altering tracking query tokens or incrementing order identification numbers in HTTP requests—an attacker can query administrative endpoints and retrieve order details belonging to other customers without authentication.
Compounding this API security flaw was a separate server configuration error. SafePal discovered that an automated data-cleanup script stopped functioning correctly between September 2025 and April 2026. Because this scheduled purge mechanism failed silently, historical order records dating back to March 2025 remained stored on active web servers rather than being archived or deleted according to retention policy. This extended data retention window drastically expanded the blast radius of the IDOR vulnerability, exposing nearly 40,000 customer records instead of just recent purchases.
SafePal received its first customer report matching this activity in early May 2026, when a customer reported receiving a suspicious phishing email and follow-up phone call claiming a critical firmware update was required for the SafePal X1 hardware wallet. SafePal initially treated the report as an isolated incident. However, following further investigation into interconnected e-commerce components and third-party logistics partners, SafePal initiated a full review and rebuild of its order-processing system in July, uncovering both the plug-in flaw and the broken data-cleanup process.
Dark Web Monetization and Social Engineering Risks
Following the breach, a threat actor listed the stolen customer dataset for sale on a cybercrime forum, an activity first spotted by threat intelligence source DarkWebInformer. To prove authenticity to potential buyers, the seller offered sample Order IDs alongside corresponding shipping countries, explicitly instructing interested buyers to test those details against SafePal’s official online breach verification tool as proof of validity. The threat actor noted in the forum post that they were seeking serious buyers and unwilling to accept low offers.
Exposed records include customer names, email addresses, phone numbers, shipping addresses, and purchase order details. For cryptocurrency users, the leak of physical shipping addresses paired with hardware wallet ownership data creates significant risk beyond standard phishing:
- Targeted Firmware Phishing: Attackers craft convincing lures referencing the user’s specific purchase history, alleging that hardware devices (such as the SafePal X1) require urgent firmware updates to fix security vulnerabilities. These lures drive victims to credential-harvesting sites designed to steal 12- to 24-word recovery seed phrases.
- Phone Vishing and Impersonation: Armed with phone numbers and exact order histories, threat actors call victims directly, impersonating SafePal support agents to walk users through fraudulent recovery procedures.
- Physical Security Concerns: Disclosing physical home addresses linked to digital asset hardware creates potential physical security risks, including home invasion or extortion attempts targeting known cryptocurrency owners.
SafePal confirmed that no wallet seed phrases, private keys, passwords, payment card numbers, bank account details, or government identification numbers were stored in the compromised database or exposed during the incident.
Blast Radius and Remediation Actions
SafePal has patched the plug-in authorization vulnerability, rebuilt its order-processing pipeline, and purged historical customer PII from active e-commerce servers, retaining only an encrypted offline copy for potential law enforcement investigations. The company engaged an external cybersecurity firm to validate the patch and audit its order-processing ecosystem. SafePal has also taken down over 30 phishing domains and fraudulent links associated with the campaign.
Crucially, because the breach was limited to order processing databases, the cryptographic security of SafePal hardware devices remains intact. Users who have not disclosed their seed phrases or private keys do not need to replace their physical wallets or move their funds.
Specific Customer Guidance
SafePal users who made purchases between March 2025 and April 2026 should adhere to the following security steps:
- Verify Exposure: Search your email for notifications sent on August 16 titled
[Important] Your SafePal Order Information Has Affected, or use SafePal’s official online verification tool by entering your order ID and shipping country. - Maintain Zero Trust for Support Lures: SafePal support will never contact you via email, SMS, or phone requesting your recovery seed phrase, private key, or password. Treat all messages demanding firmware upgrades via third-party web links as malicious.
- Emergency Migration for Exposed Keys: If you previously entered your seed phrase or private key into any web form, software prompt, or mobile app following a phishing message or call, consider your wallet compromised. Immediately generate a new seed phrase on an offline, verified SafePal hardware wallet and transfer all digital assets to the newly generated addresses.
Related content
SafePal Data Breach Exposes Order Information for 39,798 Customers
Security NewsSAP August 2026 Patch Day Addresses Critical Auth Bypass and Code Execution
Security NewsSAP Patches Maximum-Severity Commerce Cloud Vulnerability and Critical ABAP, MII Flaws
AdvisoryAuthentication Bypass via JWT alg=none in Solandra Commerce API
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call