The encryption hardware wallet manufacturer, SafePal, disclosed that a leak in a plug-in related to order tracking resulted in access to personal order information for 39,798 clients. The affected information includes the name, receiving address and contact details of the client whose name was placed between 2 March 2025 and 11 April 2026.
The company disclosed that the incident did not involve the user ' s private key, assistive words, encrypted assets, passwords, bank card information or government-issued documents. According to SafePal, the core security mechanism for the wallet was not compromised, but the users concerned were at higher risk of fishing and impersonation.
The bug is in the order tracking plugin
According to SafePal, the problem arises from a “authorization defect” in a plugin used to track customer orders. This defect may allow the attackers to view other customers ' orders and distribution information by changing the order number.
According to the company, this was a problem of access control in the order-processing chain, not the wallet itself or the asset-custody system. Incidents affect the visibility of order data and do not involve chain control of assets.
The company repaired and started the audit
According to SafePal, the loophole has been repaired and additional security measures have been added. The company stated that it had sent e-mail notifications to affected customers on a weekly basis through its security@safepal.com, and that it had engaged the Independent Third Party Security Agency to review the restoration results and check the order-processing system.
The company also stated that it would subsequently reduce the duration of personal data retention in order-processing systems to 90 days from the date of collection to reduce the exposure time for similar risks.
- Number of clients affected: 39,798
- Concerning the next single time: 2 March 2025 to 11 April 2026
- Notification: mail sent through official security mailboxes
We've got over 30 fishing stations down.
According to SafePal, more than 30 fraudulent websites and fishing links related to the incident have been identified and removed. At the same time, the company has turned on the official network verification tool to provide users with information on whether personal data has been affected.
Once again, this incident shows that the risk of hardware wallets comes not only from private key management per se, but also from peripheral systems such as orders, logistics and after-sales. For users, the follow-up risks are more focused on scenes such as impersonation of guest clothes, forgery of mail and targeted fraud.
Additional information:There have been security-related incidents in the hardware wallet industry in recent times. Previously, Térezor had also suggested that the supply chain and order system were becoming a new security pressure point for the industry because of the compliance partner ' s problems, suggesting a risk to the disclosure of customer data.
