SafePal data leak, nearly 40,000 users exposed
SafePal disclosed on 16 August that the order information of nearly 39,798 users had been disclosed because of the delegated authority deficiencies in the order tracking plugin. The records affected covered orders between 2 March 2025 and 11 April 2026, including names, e-mail addresses, mailing addresses, telephone numbers and purchase details. According to SafePal, e-mails were sent to affected customers and tools were introduced to allow buyers to use order numbers and mail orders to check in the country. The wallet provider confirmed that assistive words, private keys, wallet passwords, payment card numbers, bank account information and government-issued identity card numbers were not disclosed. SafePal also stated that it was not found that the incident affected wallet access or client funds. The company has repaired the loopholes and introduced additional access controls. SafePal stressed that the user did not need to transfer the asset because the order information was made public, but if a assistive word or private key had been entered on a suspect website, the wallet should be considered broken and a new wallet created to transfer the remaining assets。
