Executive Summary
On August 16, 2026, SafePal publicly disclosed a data breach that impacted approximately 39,798 customers. The breach resulted from an authorization flaw in the order-tracking function of a plug-in associated with customer order information. This flaw allowed unauthorized external access to customer order data, including names, email addresses, shipping addresses, phone numbers, and purchase details, for orders placed between March 2, 2025, and April 11, 2026. Critically, the breach did not compromise seed phrases, private keys, wallet passwords, bank account information, payment card numbers, or government-issued identification numbers. All affected customers were notified directly by SafePal. The company has since remediated the vulnerability, engaged a third-party security firm for audit, reduced data retention to 90 days, and taken down over 30 phishing websites linked to the breach. The primary risk to customers is increased exposure to targeted phishing and impersonation attempts. No technical indicators of compromise (IOCs) have been published as of this report. All facts are corroborated by the official SafePal disclosure, AsiaOne, and Ground News.
Technical Information
The breach originated from an authorization flaw in the order-tracking function of a plug-in used by SafePal’s order-processing system. This flaw allowed unauthorized users to access the order information of other customers under specific conditions. The vulnerability was present from March 2, 2025, to April 11, 2026. The compromised data included customer names, email addresses, shipping addresses, phone numbers, and purchase details. No wallet credentials, financial account information, or government-issued identification numbers were exposed.
The technical root cause aligns with the MITRE ATT&CK framework, specifically the "Exploit Public-Facing Application" technique (T1190), where attackers exploit vulnerabilities in web applications to gain unauthorized access. In this case, the attacker leveraged a logic flaw rather than malware or external tools. There is no evidence of lateral movement, privilege escalation, or ransomware deployment.
Following the breach, SafePal implemented several remediation steps: the vulnerability was fixed, additional security controls were introduced, and a third-party security firm was engaged to audit the fix and review the broader order-processing environment. The company also reduced the retention period for personal data in the affected system to 90 days and established a dedicated support channel for affected customers. Over 30 fraudulent websites and phishing links associated with the breach were identified and taken down.
The breach did not involve malware, and no specific threat actor has been attributed. The attack pattern is consistent with opportunistic cybercriminal activity targeting web application vulnerabilities in the cryptocurrency sector, primarily for data theft and subsequent phishing or impersonation campaigns.
Affected Versions & Timeline
The authorization flaw affected SafePal’s order-tracking plug-in from March 2, 2025, to April 11, 2026. During this period, unauthorized access to customer order information was possible. The issue was discovered and remediated prior to public disclosure on August 16, 2026. All affected customers who placed orders within the vulnerable timeframe were notified individually by email from security@safepal.com.
Key dates: March 2, 2025 – April 11, 2026: Vulnerable period for unauthorized access. August 16, 2026: Public disclosure by SafePal, customer notifications, and mitigation steps published. August 17, 2026: Major news outlets report on the breach and its implications.
Threat Activity
The primary threat activity resulting from this breach is the increased risk of targeted phishing and impersonation attacks against affected customers. The exposed data—names, email addresses, shipping addresses, phone numbers, and purchase details—can be used by attackers to craft convincing phishing emails, fraudulent phone calls, text messages, and fake support communications. SafePal has confirmed the immediate exploitation of stolen data, as evidenced by the identification and takedown of over 30 phishing websites and scam links.
There is no evidence of malware deployment, ransomware, or destructive actions. The breach was not attributed to any specific threat actor, and no technical indicators (such as IP addresses, domains, or file hashes) have been published. The attack is consistent with opportunistic cybercriminal activity targeting web application vulnerabilities for data theft and monetization through phishing.
Mitigation & Workarounds
SafePal has implemented several mitigation measures in response to the breach. The authorization flaw in the order-tracking plug-in was remediated, and additional security controls were introduced. A third-party security firm is conducting an independent audit of the fix and a broader review of the order-processing environment. The retention period for personal data in the affected system has been reduced to 90 days, subject to legal requirements. Over 30 fraudulent websites and phishing links tied to the breach have been taken down, and active monitoring for new scam infrastructure continues.
Affected customers are advised to remain vigilant for phishing and impersonation attempts. SafePal recommends never sharing seed phrases, private keys, or passwords with anyone, including individuals claiming to be SafePal support. Customers should avoid clicking links or scanning QR codes in unsolicited communications and should manually type the official SafePal web address (http://www.safepal.com) into their browser. Suspicious messages, calls, or websites should be reported through SafePal’s dedicated support channel.
No technical workarounds are required for wallet security, as wallet credentials were not compromised. However, if a customer has entered their seed phrase or private key in response to a suspicious message or website, that wallet should be treated as compromised.
Indicators of Compromise
Indicators of compromise (IOCs) are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
SafePal Official Disclosure: https://www.safepal.com/en/blog/security-update AsiaOne: https://www.asiaone.com/world/crypto-wallet-provider-safepal-discloses-data-breach-affecting-nearly-40000-users-order Ground News: https://ground.news/article/safepal-security-vulnerability-exposes-data-of-39-798-customers MITRE ATT&CK T1190: https://attack.mitre.org/techniques/T1190/ General Bytes ATM breach: https://www.facebook.com/fox13seattle/posts/security-researchers-said-a-software-flaw-may-have-allowed-attackers-to-steal-ro/1667278834992636/ OpenSea backend vulnerability: https://campuscyber.fr/wp-content/uploads/2022/07/CC_CRYPTO-ASSET-ATTACK-CATALOG_-VF.pdf Common vulnerabilities in crypto hacks: https://www.linkedin.com/top-content/technology/cybersecurity-exploit-techniques/common-vulnerabilities-in-cryptocurrency-hacks/
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor security risks in their vendor and partner ecosystems. Our platform enables continuous monitoring of supply chain exposures, rapid incident response coordination, and evidence-based risk assessments relevant to incidents such as web application vulnerabilities and data breaches. For questions or further information, contact us at info@rescana.com.

