Skip to main content
News BriefTopicSecurity

SafePal Says Order-Tracking Plugin Flaw Exposed Data for Nearly 40,000 Customers

Aug 16, 2026By ClusterWire.news· AI-assisted news brief

Crypto wallet provider SafePal disclosed a data breach that exposed order information for nearly 40,000 customers, according to reporting published on Aug. 16, 2026. The company said the incident was related to an authorization flaw in an order-tracking plugin that allowed unauthorized access to customer order data [1] [2] [3].

SafePal reported that approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 were affected, and that exposed details included customer names, email addresses, shipping addresses, phone numbers, and purchase information. Multiple reports state that seed phrases, private keys, wallet passwords, payment information, and government-issued ID numbers were not affected, and that SafePal found no evidence of wallet access or loss of customer funds [2] [3].

The breach underscores the importance of secure implementations in consumer-facing crypto services, with SafePal emphasizing that sensitive wallet credentials were not compromised [3] [4].

Was this useful?

Anonymous feedback used to improve internal story ranking. No public totals are shown.

Share

Share this article

Share this article on social platforms.

Support ClusterWire

If you find ClusterWire useful, tips help cover hosting and infrastructure costs.

We record anonymous interactions with tip buttons to understand feature usage. We do not include IP addresses, user-agent strings, or wallet addresses in these tip analytics. Blockchain transactions are public and may reveal the sending address.

Article sources

Sources

Review the sources used to produce this brief. Citations open the referenced material in a new tab.

Updates and corrections

No changes recorded in the new revision log. Earlier edits may not be included.

Coverage

Latest Coverage

Latest crypto news briefs, ordered by publication time.

Oct 3, 2026 · AI-assisted

Chainalysis ties $387M Bitget theft to North Korea; XRP reaches Bitcoin as DPRK-linked thefts top $1B

Chainalysis said AI-assisted automation reduced a bridge-reconciliation task during its investigation of the $387 million Bitget theft from more than 20 hours of manual work to …

Read more
Oct 2, 2026 · AI-assisted

NEAR Intents pauses cross-chain swaps after $3.8M exploit, gives identified attacker 48 hours to return funds

NEAR Intents general manager Alex Shevchenko said the team had identified the person responsible for a roughly $3.8 million exploit and gave them 48 hours to return the funds [1…

Read more
Oct 1, 2026 · AI-assisted

MetaMask Exits Lido Validators After Infrastructure Incident, Reports No Immediate Wallet Threat

MetaMask is responding to a security incident affecting part of its infrastructure and says it has found no immediate threat to MetaMask wallets. As a precaution, it is exiting …

Read more
Sep 28, 2026 · AI-assisted

Bitget resumes Bitcoin withdrawals in phases after $388 million hack, with fund absorbing losses

Bitget resumed Bitcoin withdrawals four days after a reported $387.5 million hack, while the exchange restores withdrawals in phases [1] [2] [3]. CEO Gracy Chen said in a Septem…

Read more
Sep 26, 2026 · AI-assisted

Bitget plans staged withdrawal restart after hack, updates losses to $388M and announces recovery bounty

Bitget plans to restart withdrawals in stages on Sept. 28, beginning with Bitcoin, with Ether, USDT and other services scheduled to follow through Oct. 2. Other reporting also l…

Read more
Sep 25, 2026 · AI-assisted

Bitget raises Sept. 24 incident estimate to $387.5M, with withdrawal plan due Sept. 26

Bitget raised its estimate of assets transferred to attacker-controlled addresses in the Sept. 24 security incident to about $387.5 million, from $351.6 million. The exchange sa…

Read more