SafePal discloses security gaps in tracking plugins: some client order information was not accessed and approximately 39,798 affected users
On 16 August, SafePal issued an official bulletin confirming that there was a security loophole in its order tracking plugin, resulting in unauthorized access to order information from some clients. Some 39,798 clients were affected, all of whom leaked information between 2 March 2025 and 11 April 2026, including names, e-mail addresses, receipt addresses, telephone numbers and purchase details. The user ' s wallet, assistive words and private keys are always secure and the incident does not involve assistive words, private keys, wallet passwords, bank account information, payment card numbers or government-issued identity documents. The problem has been repaired and additional security measures introduced. All affected clients have now been notified individually by mail and SafePal has also published an official validation page, where users can use the order number and the receiving country to check for their impact. SafePal apologizes for the incident and reminds users to refrain from disclosing assistive words, private keys or passwords to anyone, to remain vigilant about fishing and impersonation and to keep up-to-date on official blogs。
