Skip to content

Unauthorized Access To A Subset Of Customer Order Information | SFP

Safepal • August 16, 2026

We have recently identified a security incident involving unauthorized access to customer order information during a specific time frame.

This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers. SafePal never requests, collects, processes or stores such information from customers . No evidence has been found that the incident itself compromised access to SafePal wallets or funds.

However, affected order information may be used for targeted phishing and impersonation attempts, and we strongly encourage customers to remain vigilant.

Recently, the team identified an authorization flaw in the order-tracking function for a plug-in associated with customer order information. Under certain conditions, the flaw allowed unauthorized access to another customer's order information. We remediated the issue upon discovery and introduced additional security measures. (Further details our response are available in the FAQ here )

We are extremely sorry to inform the community that order information for customers who placed orders between March 2, 2025 and April 11, 2026 . Information including name, email address, shipping address, phone number, and purchase details, was accessed externally without authorization due to the flaw. The affected data involves approximately 39,798 customers .

All affected customers have been notified individually by email from [email protected] at Aug 16th with the email subject [Important] Your SafePal Order Information Has Been Affected . We encourage every customer to check their status independently. We have also published this webpage for customers to verify if they are affected using the order ID number and shipping country.

As the affected information includes detailed purchase information such as your name, details, shipping address, and order details, affected customers might be targeted by more sophisticated phishing attempts. These attempts may include fraudulent phone calls, emails, text messages, letters, refund offers, firmware-update requests, fake customer-support communications, malicious websites, or other attempts to obtain your wallet credentials or additional personal information. The affected information might also be distributed on public forums.

We take the security of all our customers very seriously. If you have received any phishing attempts, please visit this dedicated webpage to report it or us through our dedicated support channel so we can assist you directly.

The incident itself did not expose seed phrases, private keys, or wallet passwords. You should not need to move your assets solely because your order information was affected. However, if you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately. Lastly, SafePal through our official support channel.

Till this point, we have:

Alongside the above completed steps, SafePal is also working on:

Progress on the ongoing measures will be provided via updates on official channels.

For more FAQs and details, we will keep updating the dedicated webpage for this incident.

Extracted Entities

Attack Types (2)

Email Addresses (1)

MITRE ATT&CK (1)

Platforms (1)