In a current replace, non-custodial pockets SafePal mentioned it has recognized a safety incident involving unauthorized entry to buyer order info throughout a particular time-frame.
A flaw within the order-tracking plug-in led to unauthorized entry to info of a subset of shoppers. SafePal famous that order info for purchasers who positioned orders between March 2, 2025, and April 11, 2026, together with identify, electronic mail tackle, delivery tackle, telephone quantity, and buy particulars, was accessed externally with out authorization because of the flaw. The affected information includes about 39,798 prospects.
All affected prospects have been notified individually by electronic mail. The difficulty has been fastened with extra safety measures launched. A verification defect within the plugin for purchasers to trace order progress has been recognized and glued.
SafePal famous that the safety incident didn’t contain customers’ seed phrases, personal keys, pockets passwords, or different pockets credentials, checking account info, fee card numbers, or government-issued identification numbers.
The pockets supplier confirmed that {hardware} wallets, personal keys, seed phrases, and crypto property stay secure and unaffected. It’s because chilly storage structure operates in an remoted setting, fully separated from e-commerce servers. Nevertheless, uncovered order particulars could also be used for phishing makes an attempt.
What’s subsequent?
SafePal outlined the affected info as together with detailed buy info similar to customers’ names, contact particulars, delivery addresses, and order particulars; therefore, affected prospects is likely to be focused by extra subtle phishing makes an attempt.
These makes an attempt could embody fraudulent telephone calls, emails, textual content messages, letters, refund presents, firmware-update requests, faux customer-support communications, malicious web sites, or different makes an attempt to acquire your pockets credentials or extra private info.
On this gentle, SafePal urges all customers to stay vigilant, as it is going to by no means ask for his or her 12/24-word restoration phrase, PIN, or personal keys underneath any circumstances.
Because the incident itself didn’t expose seed phrases, personal keys, or pockets passwords, customers won’t want to maneuver their property. Nevertheless, a crypto pockets could also be compromised if the person has already shared or entered a seed phrase or personal key in response to a suspicious message, web site, telephone name, or letter. If so, they need to create a brand new pockets and transfer their remaining property instantly.


