Flash News

SafePal Confirms Order Tracking Plugin Vulnerability Causing Data Leak of Nearly 40,000 Customers

SafePal officially announced that its order tracking plugin has a security vulnerability, leading to unauthorized access to some customer order information, affecting approximately 39,798 customers.

The affected users are those who placed orders between March 2, 2025, and April 11, 2026. The leaked information includes names, email addresses, shipping addresses, phone numbers, and purchase details.

User wallets, mnemonic phrases, and private keys remain secure; this incident does not involve mnemonic phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification.

The issue has now been fixed, and additional security measures have been implemented. All affected customers have been individually notified via email. SafePal has also released an official verification page where users can check if they are affected using their order number and shipping country.

SafePal apologizes for the incident and reminds users not to disclose their mnemonic phrases, private keys, or passwords to anyone, and to remain vigilant against phishing and impersonation. Updates will continue to be published on the official blog.

From a market mechanism perspective, the vulnerability in the hardware wallet order system has raised user concerns about data security, potentially causing funds to temporarily flow to competitors that emphasize privacy and auditing. This incident drives the industry to strengthen order processing and plugin authorization reviews, putting pressure on affected brands while benefiting those enhancing security compliance.

Supplementary data shows that SafePal has taken down over 30 related fraudulent websites and phishing links and has hired a third-party security company to audit the remediation plan.

Source: Public Information

ABAB AI Insight

As a provider of hardware and software wallets, SafePal previously emphasized non-custodial and local key storage as core selling points. The vulnerability occurred in the order tracking plugin rather than the wallet core, indicating a historical focus on asset security while neglecting order data processing.

From a capital perspective, the company quickly fixed the vulnerability and introduced additional measures after discovering it, while notifying users and taking down phishing sites. The motivation is to control reputational damage and prevent secondary attacks, strategically rebuilding trust through transparent disclosure and verification tools.

Similar cases can be seen with other hardware wallet manufacturers experiencing data leaks in their order or customer service systems. The current cryptocurrency hardware wallet industry is transitioning from asset security to comprehensive data protection across the entire chain.

Structurally, this reflects regulatory changes: personal information leaks directly trigger user vigilance and potential compliance pressures, forcing wallet manufacturers to subject their order systems to security reviews as strict as those for private keys. Pricing power is shifting from purely asset protection to minimizing and controlling data across all business operations.

ABAB News · Cognitive Laws

  1. Asset security does not equal data security.
  2. Plugin vulnerabilities can bypass core defenses.
  3. Transparent disclosure is the starting point for trust restoration.

Source

·ABAB News
·
4 min read
·1d ago
分享: