SAFEPAL disclosed a data breach affecting approximately 39,798 customers due to a vulnerability in its order-tracking plugin. Exposed information includes customer names, email addresses, shipping addresses, phone numbers, and order details, but vital credentials like private keys and payment information remained secure. The breach occurred between March 2, 2025, and April 11, 2026, and was publicly advertised on a cybercrime forum.
SafePal has notified affected customers, fixed the vulnerability, and implemented additional security measures while monitoring for scams linked to the incident.