Skip to main content
News BriefTopicSecurity

SafePal Says Order-Tracking Plugin Flaw Exposed Data for Nearly 40,000 Customers

Aug 16, 2026By ClusterWire.news· AI-assisted news brief

Crypto wallet provider SafePal disclosed a data breach that exposed order information for nearly 40,000 customers, according to reporting published on Aug. 16, 2026. The company said the incident was related to an authorization flaw in an order-tracking plugin that allowed unauthorized access to customer order data [1] [2] [3].

SafePal reported that approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 were affected, and that exposed details included customer names, email addresses, shipping addresses, phone numbers, and purchase information. Multiple reports state that seed phrases, private keys, wallet passwords, payment information, and government-issued ID numbers were not affected, and that SafePal found no evidence of wallet access or loss of customer funds [2] [3].

The breach underscores the importance of secure implementations in consumer-facing crypto services, with SafePal emphasizing that sensitive wallet credentials were not compromised [3] [4].

Was this useful?

Anonymous feedback used to improve internal story ranking. No public totals are shown.

Share

Share this article

Share this article on social platforms.

Support ClusterWire

If you find ClusterWire useful, tips help cover hosting and infrastructure costs.

We record anonymous interactions with tip buttons to understand feature usage. We do not include IP addresses, user-agent strings, or wallet addresses in these tip analytics. Blockchain transactions are public and may reveal the sending address.

Article sources

Sources

Review the sources used to produce this brief. Citations open the referenced material in a new tab.

Updates and corrections

No changes recorded in the new revision log. Earlier edits may not be included.

Topics

Related Topics

Topics identified from the sources associated with this article.

Coverage

Latest Coverage

Latest crypto news briefs, ordered by publication time.

3h ago · AI-assisted

Cronos reports $9.19M still unrecovered after Tectonic exploit rollback reversed $111.2M

Cronos said $9.19 million remains unrecovered after an attacker borrowed $120.4 million from the Tectonic lending protocol, and validators later approved a rollback that reverse…

Read more
Sep 3, 2026 · AI-assisted

U.S. agents seize about $560,000 in cryptocurrency linked to Hamas and take over fundraising infrastructure

U.S. federal agents seized about $560,000 in cryptocurrency allegedly tied to Hamas’ military wing and took control of domains and servers used in the group’s fundraising and re…

Read more
Sep 2, 2026 · AI-assisted

Fake Claude Opus desktop app distributes RevStealer malware targeting 50+ crypto wallets on Windows

Security reporting says a fraudulent desktop application impersonating “Claude Opus 5 Free Desktop” is distributing the RevStealer malware on Windows systems [1]. The reports st…

Read more
Aug 31, 2026 · AI-assisted

More Markets reports Flow EVM lending reserve exploit draining about 15.5M WFLOW, ~$9.3M

More Markets experienced an exploit on Flow EVM that reportedly drained about 15.5 million WFLOW from the lending protocol, with Blockaid estimating the impact at roughly $9.3 m…

Read more
Aug 30, 2026 · AI-assisted

Cronos halts after Tectonic exploit, with attacker estimated to borrow about $75 million

The Cronos network halted after an exploit impacted the lending protocol Tectonic [1] [2]. Wu Blockchain reported that on-chain researcher Weilin Li estimated the attacker pumpe…

Read more
Aug 27, 2026 · AI-assisted

Bitfinex Securities raises $50 million for tokenized nickel trading backed by Alkemya assets

Bitfinex Securities said it raised $50 million in connection with a tokenized nickel trading offering, with reporting describing the security as being linked to a Luxembourg-bas…

Read more