
SafePal Order Plugin Flaw Exposed 39,798 Records; Failed Cleanup Extended Window to March 2025
SafePal disclosed an authorization flaw that leaked 39,798 customer order records. A concurrent cleanup failure extended the affected window; the dataset later appeared on criminal forums. The incident highlights retention-policy and third-party plugin risks for hardware-wallet vendors.
The exposure stemmed from an authorization bypass that let one customer view another's order data. SafePal received an initial report in early May 2026 but treated it as isolated until a July pipeline review confirmed the root cause and the separate September 2025–April 2026 data-cleanup failure. A dataset matching the exact customer count and date range later appeared for sale on a cybercrime forum.
SafePal stated no seed phrases, private keys or payment details were involved and found no evidence of wallet access. The company compared its exposure to Trezor's recent ShipMonk incident, noting Trezor's 90-day retention policy limited impact. Chainalysis documented 46 violent incidents globally through June 2026 tied to stolen crypto-holder records, with French cases rising sharply after similar tax-data leaks.
The combination of residential addresses and hardware-wallet purchases creates a ready target list for physical coercion and phishing campaigns that reference specific orders. SafePal warned customers to treat any unsolicited contact or firmware delivery as suspect. A full order-processing rebuild is underway.
Independent confirmation of the forum listing and the May–August reporting lag indicate the exposure window was wider than initially scoped and that similar plugin dependencies remain unexamined across other vendors.
Chainalysis: At least three violent incidents tied to the SafePal dataset will be recorded by December 2026.
Sources (3)
- [1]The Hacker News(https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html)
- [2]Chainalysis Crypto Crime Report 2026(https://chainalysis.com/reports/crypto-crime-2026/)
- [3]SafePal Security FAQ(https://safepal.com/security/incident-2026)