#BewareOfPhishing
Order Information Incident & Phishing Alert
At SafePal, protecting our community is our highest priority. We recently identified and fixed a verification defect in the plug-in for customers to track order progress. Your hardware wallets, private keys, seed phrases, and crypto assets are safe and unaffected. Cold storage architecture operates in an isolated environment, entirely separated from e-commerce servers.
As exposed order details may be used for phishing attempts, we urge all users to remain vigilant. SafePal will NEVER ask for your 12/24-word recovery phrase, PIN, or private keys under any circumstances.
For full details on our investigation and containment measures, please read our official report below.
Verify If You Are Affected
Report A Phishing Case
Scammers may use exposed information to contact you via email, mail, or phone. SafePal will NEVER ask for your 12/24-word recovery phrase, PIN, or private keys. Follow the steps below to handle potential phishing attempts safely. We will do our best to record and submit takedown reports with the information provided.
For Phishing Emails
Do not click any unknown URLs, images, or buttons, and never enter your recovery phrase on any page.
Click (...) in the top-right corner of the email interface, Block [Sender Name], and "Report spam" or "Report phishing" to flag to your email provider.
For Suspicious Phone Calls
Hang up immediately. SafePal employees will NEVER initiate phone calls to customers. We only communicate via official social media, official community channels, and our support ticket system. Note down the caller's phone number with any key details and make a police report. Block the phone number.
For Scam Letters
Do not scan any QR code and disregard any instructions in the letter. SafePal will NEVER send physical letters.
Make a report to local authorities if you are concerned about physical safety. Submit a photo of the letter with relevant details to the SafePal Support Portal or upload the QR code image below.
FAQ
We have contacted all affected customers separately by email on 16th August security@safepal.com with the email subject [Important] Your SafePal Order Information Has Been Affected. We encourage every customer to verify if they are affected using this webpage with their order ID number and shipping country above.
Yes, we have remediated the issue upon discovery and introduced additional security measures. In the meantime, we are engaging an independent third-party security firm to verify our fix and conduct a broader review of our order-processing system. Updates will be disclosed in future announcements.
This incident occurred solely for the order-tracking plug-in, which is independent of any other SafePal systems. No evidence has been found that the incident itself compromised access to SafePal wallets or funds.
SafePal does not have the ability to store, or collect your seed phrase, private keys, wallet password, or other wallet credentials. Your SafePal devices and wallet data remain secure.
However, affected customers may be targeted by more sophisticated phishing and impersonation attempts. We strongly encourage customers to remain vigilant.
If you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, contact SafePal through our official support channel.
We only keep order-related information as long as needed for after-sales support and warranty claims. Since this incident, we've shortened that to 90 days, after which sensitive order information is deleted. Separately, we have retained a secured offline backup of the specific records affected by this incident, solely to support potential investigations.
We first received a report consistent with this issue in early May, and treated it as an isolated case at the time, but escalated it into a formal security investigation and introduced additional protections.
As our e-commerce system involves multiple interconnected components and external integrations, as well as third-party logistics partners, we could not immediately rule out several possible explanations.
To resolve this conclusively, we began a full review and rebuild of our order-processing pipeline in July, and confirmed the root cause mentioned during the investigation. As part of the investigation, we also reached out to our third-party logistics and fulfillment partners to make sure the issue is not extended to their systems. So far, we found no evidence of external logistics data breaches.
Separately, we also found that a scheduled data-cleanup process had stopped working correctly between September 2025 and April 2026 due to a configuration error, which meant older order records stayed in the system longer than intended. That issue did not cause the unauthorized access itself, but it is why the affected range extends back to March 2025. We have since fixed this and shortened our retention window to 90 days.
Please contact us through our dedicated support channel and share the relevant details of your case. We are contacting on-chain asset-tracing specialists on this incident, and the information you provide helps support that effort, including tracing where affected assets may have moved and assisting authorities where funds can be identified.
Note that this does not represent any admission of liability or commitment to compensation; our focus at this stage is supporting recovery and ongoing investigations.
We have fixed the authorization flaw, strengthened relevant access controls, and reduced the retention period for personal information in the relevant order-processing environment to 90 days, subject to applicable legal requirements.
Relevant third-party logistics and fulfillment partners were also contacted to confirm the authorization issue did not affect their systems. An independent third-party security firm is being engaged to validate the fix and conduct a broader review of our order-processing systems. We have engaged external legal counsel and are taking appropriate steps to investigate the incident, assess its impact, and implement necessary measures to address the matter.
Over 30 fraudulent websites and phishing links tied to the scam activities have been identified and taken down, and SafePal continues to actively monitor for new ones.
Please view our latest community letter for the full incident disclosure and our next steps. If you do not trust this email or do not want to click through this link, you can also manually type our website www.safepal.com/blog into your browser to find the latest post.
Scammers might pretend to be SafePal staff or law enforcement officers contacting you for a firmware upgrade, product return, refund request, or even legal investigations.
Please do not click any links or scan any QR codes in unsolicited emails, text messages, or letters claiming to be from SafePal. You can follow the reporting guidance above on this page to report the email to your email provider and blacklist the phone number. Never share your seed phrase, private key, or password with anyone.
Official SafePal emails only come from our official domain, safepal.com. The body of a genuine email will never ask you to provide your seed phrase, private key, or password, and will never ask you to "verify your identity" or "upgrade your firmware" through a link in order to deal with some urgent situation.
When visiting our website, type our web address www.safepal.com manually into your browser rather than following a redirected link, including any link that appears to come from this notice. We have previously received reports about fraudulent websites replacing the letter ‘l’ with a capital ‘i’(I). (The website was taken down after our continuous reports.)
No. What was leaked is order-related information. It does not involve your seed phrase, your private key, or the firmware itself. The security of SafePal devices are unaffected, and you do not need to replace it or move your assets because of this incident.
However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, contact SafePal through our official support channel.