SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign — Threadlinqs Intelligence
As of 2026-08-16, SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign is a medium-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 4 indicators of compromise.
Threat ID: TL-2026-2032 · Severity: MEDIUM · Status: ACTIVE · Category: DATA_BREACH
Crypto hardware wallet vendor SafePal disclosed an authorization flaw (IDOR) in the order-tracking function of a plug-in that let customers view other customers' order records, exposing names, emails,
SafePal, a Binance-backed non-custodial hardware and software cryptocurrency wallet vendor, disclosed on August 16, 2026 that an authorization flaw in the order-tracking function of a plug-in used by its order-processing system allowed any customer to view another customer's order record by manipulating the order identifier — a classic Insecure Direct Object Reference (IDOR) / broken access control failure rather than a credential compromise. A separate configuration error caused the affected records to remain in active systems well past their intended retention period, compounding the exposure between roughly September 2025 and April 2026.
SafePal states it first received a breach-consistent customer report in early May 2026 but treated it as an isolated case rather than a systemic flaw. Public complaints describing phishing contacts that referenced accurate SafePal order details surfaced on Reddit and Trustpilot on July 3-4, 2026. SafePal began a full review and rebuild of its order-processing pipeline in July 2026, during which the authorization flaw was confirmed as the root cause. The company disclosed the incident on August 16, 2026, emailing all affected customers individually from security@safepal.com and publishing a security-update advisory.
Approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 had their name, email address, shipping address, phone number, and purchase details exposed. SafePal states that wallet seed phrases, private keys, passwords, bank account information, payment card numbers, and government-issued identification were not exposed, and it has found no evidence that the flaw itself compromised access to any SafePal wallet or funds.
A threat actor is advertising the stolen 39,798-record dataset for sale on a cybercrime forum, offering order ID and shipping-country fields as proof of possession (not independently verified by researchers). Separately, victims report a coordinated social-engineering campaign in which callers and emailers impersonate SafePal support, cite the victim's real name, address, phone, email, and order details for credibility, and direct them to fraudulent domains such as safepal.support to request a bogus 'hardware wallet replacement' or firmware update — the classic pretext used to eventually solicit a wallet seed phrase. A second, independently-flagged typosquat domain, safepal.com.co, impersonates the official SafePal wallet service and appears in both the Phishing-Database and Solflare wallet blocklist trackers, indicating the impersonation campaign extends beyond the single domain SafePal has publicly named.
SafePal's remediation includes fixing the authorization flaw and adding access-control checks, purging personal data from active servers (retaining only encrypted offline copies for law enforcement), reducing order-processing data retention to 90 days, engaging an independent third-party security firm to validate the fix and review the broader system, taking down more than 30 fraudulent websites and phishing links, and launching an order ID + shipping-country verification tool so customers can check their exposure status. SafePal advises affected customers that they do not need to replace their wallets or move funds unless they already shared a seed phrase with a phisher, and to treat any unsolicited SafePal-branded call, DM, or email as fraudulent.
Weaknesses (CWE)
CWE-639, CWE-284, CWE-459
Target sectors: cryptocurrency, financial-services, consumer-technology
Target regions: Global
Timeline
- Earliest order date within the affected window; SafePal's order-tracking plug-in authorization flaw begins exposing customer order records from this point.
- Latest order date within the affected window disclosed by SafePal; orders placed through this date fall within the 39,798-customer exposure set.
- SafePal receives its first breach-consistent customer report but treats it as an isolated incident rather than a systemic authorization flaw.
- SafePal begins a full review and rebuild of its order-processing pipeline, during which the authorization flaw is confirmed as the root cause.
- Customers post complaints on Reddit and Trustpilot describing phishing contacts that referenced accurate SafePal order details.
- SafePal publicly discloses the breach via a security-update blog post and X post, confirming 39,798 affected customers and the March 2, 2025 - April 11, 2026 exposure window.
- SafePal emails all affected customers individually from security@safepal.com.
- SafePal launches an order ID + shipping-country lookup tool at safepal.com/en/scam-protection so customers can check their exposure status.
- SafePal reports it has identified and taken down more than 30 fraudulent websites and phishing links tied to the incident.
- SafePal reduces its order-processing data-retention policy to 90 days as a remediation measure.
- BleepingComputer reports a threat actor advertising the 39,798-record stolen dataset for sale on a cybercrime forum, offering order ID and shipping-country fields as proof of possession.
Related threats
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- Balonx Sistema PhaaS Campaign — AI Voice Calls and Fake Banking Pages Targeting Mexican Financial Institutions
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness
- Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3% Detection, and Profitable Economics for Attackers
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 4 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1190, T1566.002, T1566.004, T1684.001, T1036.005, T1583.001, T1589, T1213, T1119, T1657