Order details for nearly 40,000 cryptocurrency hardware wallet buyers have surfaced on cybercrime forums following a SafePal data breach caused by an authorization flaw in an e-commerce order-tracking plug-in. The SafePal order tracking vulnerability allowed an unauthorized attacker to harvest customer names, email addresses, phone numbers, physical shipping addresses, and purchase histories for orders placed over a 13-month period.
SafePal confirmed that core cryptographic assets were not compromised during the incident. The exposed e-commerce systems operate entirely separately from hardware wallet infrastructure, meaning private keys, seed phrases, account passwords, payment card details, and government identification numbers remained secure. SafePal began notifying impacted individuals on August 16 via email under the subject line [Important] Your SafePal Order Information Has Been Affected and launched a dedicated verification tool allowing customers to check whether their purchase details were stolen.
Exploiting the SafePal Order Tracking Vulnerability
The breach resulted from a combination of an application-level logic flaw and a backend maintenance breakdown. In July, during a broader review and rebuild of its order-processing system, SafePal identified an authorization flaw within the order-tracking function of an e-commerce plug-in.
In application security terms, this defect is a classic Broken Object Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerability. When a user requests tracking details for an order, the application checks whether the request format is valid, but fails to verify if the requesting user possesses authorization to view that specific record. By automating requests with sequential or enumerated order numbers, an attacker could systematically query the tracking function and exfiltrate order data belonging to other customers across the platform.
This authorization vulnerability was rendered significantly more impactful by an internal configuration error. SafePal discovered that an automated data-cleanup script had silently stopped functioning between September 2025 and April 2026. Because order data was not purged according to standard retention schedules, sensitive customer records dating as far back as March 2, 2025, remained stored on active e-commerce servers and accessible via the flaw until April 11, 2026.
High-Risk Blast Radius for Crypto Hardware Wallet Owners
While general e-commerce breaches typically expose victims to generic spam or credit card fraud, a data leak involving hardware wallet providers creates a severe, specialized threat model. Owners of cryptocurrency hardware devices are high-value targets for cybercriminals seeking to execute targeted social engineering attacks or physical extortion.
By combining physical addresses with phone numbers, emails, and purchase confirmation, threat actors obtain a complete roadmap to execute high-efficiency phishing campaigns:
- Targeted Phishing and Fake Firmware Update Attacks: Threat actors leverage knowledge of specific product purchases to craft highly convincing lures. As early as May 2026, SafePal users reported receiving suspicious emails and phone calls claiming that a security flaw had been identified in the SafePal X1 hardware wallet, instructing them to install a mandatory firmware update. These malicious links direct users to fake interfaces designed to capture 12- or 24-word recovery seed phrases.
- Vishing and Support Impersonation: Attackers posing as SafePal customer service or legal representatives contact victims directly by phone, citing real order numbers and delivery addresses to build immediate credibility before attempting to trick the victim into revealing access credentials or transferring assets.
- Physical Security Risks: Revealing physical residential addresses of cryptocurrency holders introduces real-world physical threat vectors, including supply chain interception of replacement devices or targeted home coercion attacks.
Dark Web Monetization and Verification Abuse
Following the exposure, a threat actor listed the stolen dataset for sale on a prominent cybercrime forum, as spotted by threat intelligence researcher DarkWebInformer. The seller claimed to possess the complete set of 39,798 customer records matching the exact timeframe disclosed in SafePal’s advisory.
To prove the legitimacy of the stolen database to prospective buyers, the threat actor offered sample order IDs and shipping countries, explicitly instructing interested buyers to test those details against SafePal’s newly launched online verification tool. This tactic demonstrates how public breach lookup tools can be weaponized by extortionists to validate stolen datasets for potential buyers. SafePal has since purged personal data from active e-commerce servers—retaining an encrypted offline copy for law enforcement—and coordinated the takedown of over 30 fraudulent phishing domains tied to the leak.
Specific Defensive Guidance for SafePal Users
If you ordered hardware wallets or accessories from SafePal between March 2025 and April 2026, take the following immediate protective steps:
- Use the Official Verification Tool Directly: If you wish to check your order status, navigate directly to SafePal’s official domain (
safepal.com). Do not click on links provided in emails, SMS messages, or forum posts. - Never Input Seed Phrases or Private Keys Online: SafePal device firmware updates are delivered strictly through official desktop applications or mobile apps connected via Bluetooth or QR codes. SafePal will never request your seed phrase, private key, or password via an email link, phone call, or web form.
- Remediate Exposed Recovery Phrases Immediately: You do not need to replace your physical SafePal hardware wallet or move funds simply because your order history was exposed. However, if you previously entered your seed phrase or private key into any web form, email link, or third-party interface following a phone call or email prompt, consider that wallet compromised immediately. Generate a brand-new seed phrase on a factory-reset, offline SafePal device and transfer all assets to the new wallet addresses right away.
- Ignore Inbound Urgent Alerts: Disregard unsolicited phone calls, SMS messages, or emails citing urgent legal investigations, product recalls, or mandatory device firmware updates. Assume any inbound outreach referencing your hardware wallet purchase history is malicious.
Related content
SafePal Customer Data Breach Exposes 40,000 Order Records
Security NewsSAP August 2026 Patch Day Addresses Critical Auth Bypass and Code Execution
Security NewsSAP Patches Maximum-Severity Commerce Cloud Vulnerability and Critical ABAP, MII Flaws
AdvisoryAuthentication Bypass via JWT alg=none in Solandra Commerce API
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call