Unauthorized Access To A Subset Of Customer Order Information

Aug 16,2026

We have recently identified a security incident involving unauthorized access to customer order information during a specific time frame.

This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers. SafePal never requests, collects, processes or stores such information from customers. No evidence has been found that the incident itself compromised access to SafePal wallets or funds. 

However, affected order information may be used for targeted phishing and impersonation attempts, and we strongly encourage customers to remain vigilant.

What Happened

Recently, the team identified an authorization flaw in the order-tracking function for a plug-in associated with customer order information. Under certain conditions, the flaw allowed unauthorized access to another customer's order information. We remediated the issue upon discovery and introduced additional security measures. (Further details about our response are available in the FAQ here)

We are extremely sorry to inform the community that order information for customers who placed orders between March 2, 2025 and April 11, 2026. Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves approximately 39,798 customers.

All affected customers have been notified individually by email from security@safepal.com at Aug 16th with the email subject [Important] Your SafePal Order Information Has Been Affected. We encourage every customer to check their status independently. We have also published this webpage for customers to verify if they are affected using the order ID number and shipping country.

What This Means for Affected Customers

As the affected information includes detailed purchase information such as your name, contact details, shipping address, and order details, affected customers might be targeted by more sophisticated phishing attempts. These attempts may include fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information. The affected information might also be distributed on public forums.

We take the security of all our customers very seriously. If you have received any phishing attempts, please visit this dedicated webpage to report it or contact us through our dedicated support channel so we can assist you directly.

The incident itself did not expose seed phrases, private keys, or wallet passwords. You should not need to move your assets solely because your order information was affected. However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, contact SafePal through our official support channel.

What We Have Done & Next Steps

Till this point, we have: 

  • Fixed the issue and implemented additional security measures. An independent third-party security firm is being engaged to validate the fix and conduct a broader review of our order-processing systems.
  • Tightened the retention period for personal information in the relevant order-processing environment to 90 days, subject to applicable legal requirements.
  • Opened a dedicated support channel for this incident so that every affected customer receives a direct, tracked response.
  • Identified and informed all affected customers separately by email with the full disclosure where possible.
  • Contacted relevant third-party logistics and fulfillment partners to investigate and confirm the issue had not spread further within their systems.
  • Identified and taken down over 30 fraudulent websites and phishing links tied to the scam activities, with continued active monitoring for new ones.

Alongside the above completed steps, SafePal is also working on: 

  • Following up with the independent third-party security firm on audits for the fix and broader review of our order-processing system. Any updates will be disclosed in the official blog. 
  • Continuously collecting user reports and monitoring new scamming activities to further take down fraudulent websites and domains

Progress on the ongoing measures will be provided via updates on official channels.

What we recommend you do

  1. Never share your seed phrase, private key, or password with anyone, including someone presenting themselves as SafePal support. We will never ask you for this by phone, by email, or through any other channel under any circumstance. 
  2. Do not click links or scan QR codes in unsolicited emails, text messages, or letters claiming to be from SafePal. If you receive malicious emails from scammers, report them to your email provider.
  3. Type our web address http://www.safepal.com manually into your browser rather than following a redirected link, including any link that appears to come from this notice. We have previously received reports about fraudulent websites replacing the letter ‘l’ with a capital ‘i’(I). (The website was taken down after our continuous reports.)
  4. Stay vigilant for any suspicious outreach or impersonations. Treat any unexpected contact or hardware delivery referencing your SafePal purchase as suspect, whether it arrives by phone, in the post, or in person. 
  5. Report anything suspicious, such as messages, calls, letters, or websites, through our dedicated webpage. Do not reach out via social media for the interests of your privacy.

For more FAQs and details, we will keep updating the dedicated webpage for this incident.

近期文章