SafePal: Safepal security vulnerability exposes data of 39,798 customers

SafePal: Safepal security vulnerability exposes data of 39,798 customers

SafePal Discloses Data Breach Exposing Customer Personal Information

SafePal, a provider of crypto hardware wallets and security solutions, has reported a security incident that exposed the personal data of thousands of customers. The breach, disclosed on Sunday, involved an "authorization flaw" in a plug-in used to track customer orders, allowing unauthorized access to sensitive information.

The exposed data included names, physical addresses, and contact details, increasing the risk of phishing and impersonation attacks for affected users. However, SafePal confirmed that no cryptocurrency funds, passwords, or private wallet keys were compromised in the incident.

The vulnerability stemmed from a flaw in the order-tracking system, which functioned similarly to a retail receipt lookup where altering an order number could reveal another customer’s delivery details. SafePal has not disclosed the exact number of impacted users.

This breach follows a recent high-profile attack on Coldcard hardware wallets, where attackers reportedly stole at least $120 million in Bitcoin. While these incidents do not indicate a systemic flaw in hardware wallets, they underscore the persistent risks in crypto storage solutions and the importance of risk assessment in asset management.

Source: https://www.coindesk.com/tech/2026/08/16/crypto-wallet-safepal-reveals-a-data-breach-exposing-nearly-40-000-customers-order-info

SafePal TPRM report: https://www.rankiteo.com/company/safepal

"id": "saf1786970142",
"linkid": "safepal",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Thousands (exact number '
                                              'undisclosed)',
                        'industry': 'Cryptocurrency, Cybersecurity, Hardware '
                                    'Wallets',
                        'name': 'SafePal',
                        'type': 'Company'}],
 'attack_vector': 'Authorization Flaw',
 'customer_advisories': 'Public disclosure of breach to inform affected '
                        'customers',
 'data_breach': {'personally_identifiable_information': 'Names, physical '
                                                        'addresses, contact '
                                                        'details',
                 'sensitivity_of_data': 'High (PII)',
                 'type_of_data_compromised': 'Personal Information'},
 'description': 'SafePal, a provider of crypto hardware wallets and security '
                'solutions, reported a security incident involving an '
                "'authorization flaw' in a plug-in used to track customer "
                'orders, allowing unauthorized access to sensitive customer '
                'data. The exposed data included names, physical addresses, '
                'and contact details, increasing the risk of phishing and '
                'impersonation attacks. No cryptocurrency funds, passwords, or '
                'private wallet keys were compromised.',
 'impact': {'brand_reputation_impact': 'Undermined trust in crypto storage '
                                       'solutions',
            'data_compromised': 'Names, physical addresses, contact details',
            'identity_theft_risk': 'Increased risk of phishing and '
                                   'impersonation attacks',
            'systems_affected': 'Order-tracking system plug-in'},
 'lessons_learned': 'Underscores persistent risks in crypto storage solutions '
                    'and the importance of risk assessment in asset management',
 'post_incident_analysis': {'root_causes': 'Authorization flaw in '
                                           'order-tracking system plug-in'},
 'references': [{'source': 'SafePal Public Disclosure'}],
 'response': {'communication_strategy': 'Public disclosure of breach'},
 'title': 'SafePal Data Breach Exposing Customer Personal Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Flaw in order-tracking system plug-in allowing '
                            'unauthorized access via order number manipulation'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.