SafePal disclosed a security incident involving an authorization flaw in its order-tracking plugin that allowed unauthorized parties to access customer order data. The company said 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 were affected.

The exposed data included names, email addresses, shipping addresses, phone numbers and purchase details. SafePal said seed phrases—the recovery words that control wallet access—along with private keys, wallet passwords, payment information and government-issued ID numbers were not compromised.

The flaw was an authorization error inside the order-tracking plugin SafePal uses to let customers check shipment status. Because the plugin failed to enforce proper access controls, unauthorized parties were able to read order records belonging to other customers. SafePal said it patched the vulnerability and deployed additional security measures after discovering it.

SafePal sent individual email notifications to every affected customer. The company also published a status-check page on its website where customers can verify whether their own account was included in the exposure.

The practical risk from this breach centers on social engineering. The stolen data package—full name, phone number, home shipping address and purchase history tied to a hardware wallet order—gives bad actors the specific details they need to impersonate SafePal's support team. Reports from affected customers indicate scammers have already placed phone calls citing accurate personal and order information, then attempted to persuade targets to accept a replacement hardware wallet or surrender their seed phrase.

SafePal warned users to treat any inbound messages about their account with suspicion and to use only official channels for support. The company told customers not to share their seed phrase, private key or wallet password with anyone under any circumstances, and recommended changing their wallet password as a precaution.

Hardware wallet customers are a high-value target for this type of attack because the merchandise itself signals that the buyer holds crypto self-custody. A verified shipping address linked to a hardware wallet purchase tells a scammer not just who to call, but that the target likely holds digital assets outside an exchange—making direct-seizure social engineering worth the effort.

Customer reports published on Reddit and in reviews of SafePal's service describe callers who recited home addresses and full order details before attempting to collect seed phrases under the pretense of a product recall or security upgrade. SafePal has not confirmed how many customers received fraudulent contact attempts following the exposure.

SafePal did not disclose when it first identified the authorization flaw or how long it operated between initial discovery and the patch. The window covered in the incident—March 2, 2025 to April 11, 2026—spans more than 13 months of orders, which accounts for the breadth of the exposure.

Affected customers should verify inbound calls and emails against SafePal's official website before taking any action, avoid clicking links in messages claiming to be from SafePal and treat any request for a seed phrase or private key as a confirmed scam regardless of how much personal information the caller already has.