Threat Intelligence Brief
Curated summary with source attribution
Source: tradingview.com
Threat Risk: Medium
Victim: SafePal users
Incident: Data breach disclosing order information for approximately 40,000 users.
Impact: Exposure of sensitive order data, increasing risk of targeted phishing campaigns.
Attacker: Unidentified threat actors
Analysis: The breach involves the leak of order-related data, which can be leveraged for targeted social engineering and phishing attacks. While core wallet keys are not reported as compromised, the exposure of purchase history and user details significantly increases the attack surface for the affected customers.
Recommendations: Enable multi-factor authentication on all linked accounts; Be vigilant against phishing emails targeting SafePal users; Monitor accounts for unauthorized activity
Source: Reuters via TradingView
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-16 17:34 UTC
Data breach resulting from an authorization flaw in the order tracking system. Exposure of personal and purchase data for approximately 39,798 users, facilitating targeted phishing. An authorization vulnerability allowed unauthorized access to customer names, addresses, and purchase history over a prolonged period. While critical wallet security assets like seed phrases and private keys remained secure, the leaked PII provides attackers with high-fidelity data for social engineering. The discovery of over 30 fraudulent websites indicates that the stolen data is already being actively weaponized.
Corroborating source: reuters.com
Update — 2026-08-16 17:34 UTC
Data breach exposing order and contact information of approximately 40,000 users. Potential for targeted phishing attacks and social engineering. The breach specifically targeted order-related data and contact information rather than wallet security credentials. While funds are not directly at risk, the leaked PII provides a roadmap for attackers to launch convincing phishing campaigns. This highlights the persistent risk that ancillary data breaches pose to cryptocurrency users.
Corroborating source: pluang.com
Update — 2026-08-16 19:18 UTC
A data breach occurred due to an authorization flaw in an order-tracking plugin. The personal information, including names and addresses, of 39,798 customers was exposed. Attackers exploited an authorization vulnerability in a plugin to view customer receipts and delivery details. The breach leaked names and physical addresses but did not compromise core wallet security or private keys. This incident demonstrates how vulnerabilities in peripheral administrative systems can be leveraged for social engineering against high-value targets.
Corroborating source: coindesk.com
Update — 2026-08-16 20:19 UTC
Unauthorized access to customer order information due to a plugin flaw. PII exposure for approximately 39,798 users, increasing the risk of targeted phishing. The breach stemmed from a verification defect in an order-tracking plugin used for e-commerce transactions. While critical wallet credentials and assets remain secure due to isolated cold storage architecture, the leak of names, addresses, and phone numbers creates a high risk of highly personalized phishing. Attackers will likely leverage specific purchase history to deceive users into revealing their private keys.
Corroborating source: tradingview.com
Update — 2026-08-16 21:30 UTC
Data breach caused by an authorization flaw in an order-tracking plugin. Exposure of PII for approximately 40,000 users, increasing the risk of targeted phishing. The breach stemmed from a broken access control mechanism in an order-tracking plugin, allowing unauthorized access to customer PII. While sensitive wallet credentials and seed phrases remained secure, the exposure of shipping and contact details provides a rich dataset for social engineering. A failure in automated data retention policies further extended the window of exposure for older records.
Corroborating source: crypto.news
Update — 2026-08-16 22:01 UTC
Unauthorized access to customer order information via a vulnerable order-tracking plugin. Personal identifying information of 39,798 customers was exposed, increasing the risk of targeted phishing. The breach resulted from a flaw in an order-tracking plugin, exposing PII including names, emails, and shipping addresses. While the air-gapped hardware wallets and private keys remain secure, the leaked data provides a roadmap for attackers to conduct targeted social engineering. The specific nature of the victim pool—hardware wallet owners—makes these individuals high-value targets for sophisticated phishing campaigns.
Corroborating source: gizmodo.com
Update — 2026-08-16 22:41 UTC
Data breach via an authorization error in an order tracking plugin. Exposure of names, delivery addresses, phone numbers, and emails for approximately 40,000 users. The breach originated from an authorization vulnerability in a tracking plugin that allowed unauthorized access to customer order data. While core security assets like seed phrases and private keys remained untouched, the leaked PII provides attackers with the necessary context for targeted phishing. This incident underscores the systemic risk posed by insecure third-party plugins in the crypto supply chain.
Corroborating source: forklog.com
Update — 2026-08-17 00:32 UTC
A data breach occurred due to an authorization flaw in an order-tracking system. Personal information of approximately 39,798 customers was exposed, facilitating targeted phishing. An authorization flaw in SafePal’s order-tracking system allowed unauthorized access to customer PII. While cryptographic keys remain secure, the exposed data is being used for highly targeted social engineering campaigns. This incident mirrors a broader trend of attackers targeting the commerce and shipping pipelines of hardware wallet providers.
Corroborating source: primexbt.com
Update — 2026-08-17 00:43 UTC
Data breach caused by an authorization flaw in an e-commerce plugin. Exposure of PII for approximately 39,798 users, leading to targeted phishing campaigns. The breach stemmed from an Insecure Direct Object Reference (IDOR) vulnerability, allowing attackers to view order details by simply altering order numbers. While cryptographic keys remained secure on an isolated network, the leak of physical addresses and phone numbers enables highly convincing social engineering attacks. The three-month delay between the first report and public disclosure indicates a lapse in the company’s incident response timeline.
Corroborating source: startupfortune.com
Update — 2026-08-17 03:04 UTC
Data breach resulting from a malfunctioning order-tracking plugin. Exposure of PII and shipping addresses for 39,798 users, increasing risks of phishing and physical theft. A vulnerability in a plugin used for order tracking allowed unauthorized actors to access customer PII, including shipping addresses and phone numbers. While seed phrases and private keys were not compromised, the exposure of physical addresses increases the risk of targeted ‘wrench attacks.’ The incident highlights the danger of third-party plugin vulnerabilities in the hardware wallet supply chain.
Corroborating source: news.bitcoin.com
Update — 2026-08-17 03:04 UTC
Exploitation of an e-commerce order-tracking flaw resulting in a data breach. Exposure of PII for approximately 39,798 customers, increasing the risk of targeted phishing. The breach originated from a flaw in the e-commerce system, allowing attackers to harvest customer shipping and contact details. While core wallet security and private keys remain intact, the exposure of PII enables highly convincing social engineering attacks. The subsequent sale of this data on cybercrime forums indicates a persistent threat to the affected user base.
Corroborating source: bleepingcomputer.com
Update — 2026-08-17 06:18 UTC
An authorization flaw in an order-tracking system exposed customer personal information. Personal data of approximately 39,798 customers was leaked, increasing the risk of targeted phishing. An authorization vulnerability allowed unauthorized access to customer order data for over a year. While cryptographic keys and funds remained secure, the exposure of physical addresses and purchase history significantly increases the risk of social engineering. The emergence of over 30 fraudulent websites indicates that attackers are already attempting to weaponize the stolen data.
Corroborating source: bitcoinke.io
Update — 2026-08-17 06:18 UTC
Unauthorized access to personal customer information via a flaw in an order-tracking plug-in. Exposure of PII for 40,000 users, significantly increasing the risk of targeted phishing and impersonation. The breach occurred due to a vulnerability in a customer order-tracking plug-in, exposing names, emails, and shipping details. While core cryptographic assets like seed phrases remain secure, the leaked PII provides attackers with the context needed for convincing phishing campaigns. This incident emphasizes how vulnerabilities in non-core administrative systems can still jeopardize user security through secondary attack vectors.
Corroborating source: tradingview.com
Update — 2026-08-17 10:01 UTC
Data breach of customer PII via an order-tracking plugin flaw. Leak of names, addresses, and purchase history for ~39,798 users, increasing the risk of physical theft and phishing. The breach exposed a dangerous combination of home addresses and proof of cryptocurrency ownership. While seed phrases remained secure, the leak enables attackers to identify and physically target high-net-worth individuals. This incident follows a trend of supply chain and plugin vulnerabilities impacting hardware wallet providers.
Corroborating source: decrypt.co
Update — 2026-08-17 10:01 UTC
Data breach resulting from a flaw in an order-tracking plug-in. Exposure of PII for approximately 39,798 customers, increasing the risk of physical theft and extortion. The breach exposed PII, including home addresses and phone numbers, which directly links real-world identities to crypto hardware ownership. While seed phrases remained secure, the leak provides a roadmap for ‘wrench attacks’ and physical extortion. This incident underscores a recurring weakness in the supply chain and shipping logistics of hardware wallet providers.
Corroborating source: finance.yahoo.com
Update — 2026-08-17 10:43 UTC
An authorization flaw in an order-tracking plugin leaked customer PII. Exposure of names, addresses, and phone numbers for 39,798 users, increasing the risk of targeted phishing. The breach stemmed from an authorization flaw that allowed users to view others’ order histories. While core wallet security and private keys remain intact, the leaked PII is now being auctioned on cybercrime forums. This specific combination of shipping and purchase data enables attackers to craft highly convincing impersonation scams.
Corroborating source: helpnetsecurity.com
Update — 2026-08-17 14:09 UTC
Data breach involving the theft of customer order information. Exposure of PII for approximately 40,000 users, significantly increasing the risk of targeted phishing scams. The breach stemmed from a vulnerability in a customer order information plugin compounded by a system bug that retained data longer than intended. While critical wallet credentials like seed phrases remained secure, the theft of names, emails, and phone numbers provides a roadmap for sophisticated social engineering. The subsequent sale of this dataset on cybercrime forums indicates an active threat to the affected user base.
Corroborating source: securityweek.com
Update — 2026-08-17 15:54 UTC
Data breach via an authentication flaw in an order-tracking system. Exposure of PII for 39,798 customers, significantly increasing the risk of targeted phishing campaigns. An authentication vulnerability in a customer order-tracking system allowed unauthorized access to PII, including shipping addresses and purchase histories. While critical wallet secrets and financial data remain secure, the leaked data enables attackers to craft highly convincing impersonation attacks. The emergence of fraudulent domains like ‘safepal.support’ indicates that the stolen data is already being weaponized for phishing.
Corroborating source: en.bloomingbit.io
Update — 2026-08-17 19:20 UTC
A data breach caused by an authorization flaw in an order-tracking plug-in. Personal information of nearly 40,000 customers was exposed, increasing the risk of targeted phishing attacks. An authorization flaw in an order-tracking plug-in allowed attackers to view customer receipts by simply modifying order numbers. While core wallet security and private keys remain intact, the leak of physical addresses and contact info enables high-confidence impersonation. This incident demonstrates how vulnerabilities in non-critical ancillary systems can compromise user safety.
Corroborating source: northeasttimes.com
Update — 2026-08-17 23:17 UTC
An authorization flaw in an order-tracking plug-in led to the exposure of customer PII. Personal identification and purchase history for nearly 40,000 users were leaked to cybercrime forums. The breach stemmed from an authorization flaw in an e-commerce plug-in combined with a failure in data retention policies. Although private keys were not compromised, the leaked data provides attackers with a verified list of cryptocurrency hardware users. This enables highly targeted social engineering campaigns designed to steal seed phrases.
Corroborating source: safestate.com
Update — 2026-08-18 16:17 UTC
Data breach via an authorization flaw in an order-tracking plug-in. Exposure of PII for approximately 40,000 users, leading to heightened phishing risks. An authorization vulnerability in SafePal’s order-tracking system allowed attackers to exfiltrate personal details of nearly 40,000 customers. The stolen data, including phone numbers and addresses, is now available on cybercrime forums. While core wallet credentials were not compromised, the breach significantly increases the risk of highly targeted social engineering attacks.
Corroborating source: cybernews.com
Update — 2026-08-22 20:04 UTC
Data breach resulting from an authorization flaw in an order-tracking plug-in. Exposure of PII for approximately 39,798 customers, increasing risks of targeted phishing and physical threats. An authorization flaw in a SafePal plug-in allowed unauthorized access to customer order records. The breach exposed PII including names, emails, and physical addresses, effectively tagging these individuals as hardware wallet owners. This increases the likelihood of highly targeted social engineering and physical security risks.
Corroborating source: galaxywarden.com