A major security alert from SafePal has come to light for crypto users. According to the company, due to an authorization flaw, order-related information of approximately 39,798 users became accessible to unauthorized individuals.
In this incident, users’ names, email addresses, phone numbers, shipping addresses, and purchase details made with SafePal were included. However, SafePal has clarified that seed phrases, private keys, wallet passwords, payment information, and government-issued IDs were not exposed in this breach.
This difference is very important, because there is no evidence that exposed information could directly give access to wallet funds. According to SafePal, it also found no evidence that customers’ wallets or funds were compromised as a result of this incident.
What was the root issue?
According to SafePal, the problem stemmed from an authorization defect in an order-tracking plugin. In some cases, this vulnerability could allow a person to view another customer’s order information.
The company first received a phishing report related to this issue in May. Later in July, a full security investigation was launched, during which the software flaw was confirmed and fixed.
Another issue also came to light. According to SafePal, due to a configuration error in the data-cleanup process, some older order records could not be deleted on time. This extended the duration of the affected data.
What is the real risk for crypto users?
The biggest risk in this incident is phishing scams.
If scammers have a user’s name, address, and purchase details, they can create a fake email, message, or website that appears legitimate. The goal may be to trick the user into giving away their seed phrase, private key, or wallet password.
SafePal reported that it identified and removed more than 30 fraudulent websites and phishing links.
Users should be especially cautious of messages that urge them to immediately verify their wallet, transfer funds, or enter a recovery phrase.
What actions did SafePal take?
In addition to fixing the vulnerability, the company introduced extra access controls. In the relevant environment, the personal data retention period was reduced to 90 days, and an independent security firm is also conducting a further review of the systems.
SafePal says it has not yet found any evidence that the issue spread to the systems of logistics or fulfillment partners.
What should users do?
If you are a SafePal customer, you don’t need to move your crypto assets just because some order information was exposed. However, be extremely careful in phishing cases.
Do not share your seed phrase, private key, or wallet password with any person, website, or support agent.
If a user has already entered their seed phrase or private key on a suspicious website, they should consider it compromised and create a new wallet securely to transfer the remaining assets.
SafePal’s incident once again reminds us that crypto security is not limited to blockchain or wallet technology. Personal data can also become a powerful weapon for scammers.
