On 16 August 2026, SafePal published a notice saying it had found an authorization flaw in the order-tracking function of one of its own plug-ins. Under certain conditions, that flaw let someone on the outside look at another customer's order records. SafePal says orders placed between 2 March 2025 and 11 April 2026 were affected, and that the records belonged to about 39,798 customers. What sat in those records: names, email addresses, shipping addresses, phone numbers and purchase details.
The company says seed phrases, private keys, wallet passwords, bank-account information, payment-card numbers and government-issued identification numbers were not involved, and it found no evidence that wallets or funds were compromised. It says the flaw was fixed when it was found, that it emailed every affected customer from [email withheld] on 16 August 2026, and that it checked logistics partners and saw no sign the problem had spread there. It is aware of claims that the dataset is being offered for sale, and says it cannot verify those claims.
Your keys were not taken. Your name and home address may have been.
Almost every account of this incident leads with what was not stolen. That part is true, and it is not reassurance. A SafePal order record is a document that says: this named person, at this address, with this phone number and this email, bought a crypto wallet or another SafePal product. Nobody needs a seed phrase to use that.
Someone holding that list can write to you as if they already know your order. They can call. They can treat the shipping address as a house that is more worth visiting, watching, or pressuring than the house next door. For people who keep hardware wallets at home, the dangerous part of a shipping leak has always been the address book, not the device in the box.