Full research report
SafePal data breach impacts 39,798 customers, stolen info for sale
Executive assessment
SafePal's August 2026 disclosure confirms that an authorisation control failure in a third-party e-commerce order-tracking plug-in enabled an unknown threat actor to exfiltrate personal order data for nearly 40,000 hardware wallet customers across a roughly 13-month window. A compounding configuration error that silently disabled scheduled data-cleanup jobs between September 2025 and April 2026 retained records beyond the intended window and expanded the accessible data pool, making the breach scope wider than the plug-in flaw alone would have permitted. The most operationally significant finding is the pre-disclosure exploitation gap: Reddit and Trustpilot victim complaints from July 2026 document scammers already in possession of accurate personal order details at least three months before SafePal issued formal customer notification, indicating a meaningful lag between breach awareness and public warning. The threat actor is now selling the dataset on a cybercrime forum—confirmed by DarkWebInformer—while SafePal has removed more than 30 associated fraudulent websites; no cryptocurrency assets or wallet credentials are confirmed compromised, but highly targeted phishing and social-engineering attacks against identified hardware wallet owners represent the primary ongoing risk.
What happened
SafePal disclosed on 16 August 2026 that an authorisation flaw in a third-party order-tracking plug-in had allowed an unknown threat actor to exfiltrate order records belonging to approximately 39,798 customers who purchased between 2 March 2025 and 11 April 2026. SafePal first received a report consistent with the breach in early May 2026 but initially treated it as an isolated case; a formal investigation launched in July 2026 identified both the plug-in vulnerability and a compounding configuration error that had disabled data-cleanup automation between September 2025 and April 2026, extending the window of accessible records. Customer reports of targeted phishing calls and emails citing accurate order details surfaced from May 2026—three months before formal disclosure—indicating the stolen data was weaponised well before affected users were warned. The dataset subsequently appeared on a cybercrime forum, with the listing corroborated by DarkWebInformer.
Affected scope
Approximately 39,798 SafePal e-commerce customers who placed orders between 2 March 2025 and 11 April 2026; exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. SafePal hardware wallet applications (S1, S1 Pro, X1) and cryptographic credentials—seed phrases, private keys, passwords—are not affected. No financial account or government-issued identification data was exposed.
Technical assessment
The root cause was an authorisation control failure in a plug-in component of SafePal's order-tracking system, consistent with an insecure direct object reference weakness: order records could be retrieved without adequate verification that the requester owned the queried record. A secondary configuration error caused a scheduled data-cleanup process to fail silently between September 2025 and April 2026, retaining records beyond the intended window and expanding the accessible data pool. The vulnerability was confined to the e-commerce order layer; no cryptographic material, payment data, or wallet infrastructure was within scope.
Recommended defensive actions
- Verify whether your order is affected using SafePal's official lookup tool at safepal.com, providing your order ID and shipping country—access only via the official domain.
- Inspect any SafePal email, phone, or SMS communication for spoofing indicators; do not share wallet credentials or act on firmware-update, refund, or device-replacement requests without verifying the contact through official channels.
- Audit e-commerce and order-management plug-ins for authorisation flaws, particularly insecure direct object references on order-retrieval endpoints, and enforce session-bound least-privilege access controls.
- Implement monitoring and alerting on data-retention automation to detect failed cleanup jobs that cause unintended accumulation of customer personal data beyond the defined retention window.
- Monitor for newly registered domains impersonating your organisation; subscribe to domain-monitoring services and take down fraudulent infrastructure promptly, as SafePal required removal of 30-plus fraudulent sites following this incident.
Uncertainties and evidence gaps
- The identity and affiliation of the threat actor offering the data on a cybercrime forum have not been confirmed; no known group has been attributed.
- The precise mechanism by which the attacker discovered or obtained access to the authorisation flaw is not publicly disclosed.
- Whether the May 2026 phishing reports reflect the same exfiltration event or a separate, earlier unauthorised access has not been confirmed by SafePal.
- The specific third-party plug-in vendor and logistics partners implicated have not been named publicly.
- The total volume of data actually exfiltrated versus the maximum exposure ceiling of 39,798 records has not been independently verified.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Confirmed exploitation: an unknown threat actor exploited an authorisation flaw in SafePal's order-tracking plug-in to exfiltrate data from approximately 39,798 customers; the stolen dataset is now being offered for sale on a cybercrime forum and has been used in active phishing and social-engineering campaigns against SafePal customers since at least May 2026.
Investigation began with the BleepingComputer article and SafePal's official security advisory as primary anchors; both were fetched and confirmed. Searches identified multiple independent outlets and located the vendor's official security update page. CoinDesk, CryptoBriefing, and The Block provided independent corroboration across four verified domains. No CVE has been assigned, no public exploit code exists, and the threat actor remains unattributed. A material finding emerged from The Block: Reddit and Trustpilot victim complaints from July 2026 record scammers already in possession of accurate personal order details, establishing that the stolen data was actively weaponised at least three months before SafePal issued formal customer notification.
- What are the confirmed facts of the SafePal breach per the primary reporting outlet?Fetched BleepingComputer article directly.bleepingcomputer.com ↗
39,798 customers affected between March 2025 and April 2026; authorisation flaw in an order-tracking plug-in; data listed for sale on a cybercrime forum per DarkWebInformer; phishing emails and phone calls reported from May 2026; no CVE assigned.
why Establishes the primary event facts and timeline; identifies the cybercrime forum listing and phishing campaign as downstream consequences requiring further corroboration.
- Does SafePal's official advisory corroborate the reported facts and provide additional technical or remediation detail?Searched for and fetched SafePal's official security advisory page.safepal.com ↗
Vendor confirms authorisation flaw, 39,798 affected records, compounding data-retention configuration error from September 2025 to April 2026, 30-plus fraudulent sites removed, independent third-party audit engaged, data purged from active servers. No CVE assigned.
why First-party advisory is authoritative on scope, remediation completeness, and what data was not compromised; the confirmed secondary retention error materially expands the breach explanation.
- Does CoinDesk provide independent corroboration and any new technical or policy detail?Fetched CoinDesk article.coindesk.com ↗
All core facts confirmed. Flaw characterised as analogous to accessing another customer's receipt by changing the order number in a tracking system. New detail: SafePal has set a going-forward 90-day data-retention limit.
why Independent corroboration from a major cryptocurrency outlet; the 90-day retention policy is a concrete defensive improvement and confirms the vendor has addressed the systemic retention issue.
- What do further independent outlets report on the phishing campaign and dark-web activity, and can DarkWebInformer reporting be corroborated?Fetched CryptoBriefing article; searched for DarkWebInformer-specific reporting on the SafePal listing.cryptobriefing.com ↗
No threat-actor attribution in any source; phishing campaign included the fraudulent site safepal.support; DarkWebInformer confirmed as source for cybercrime forum report but no verified standalone DarkWebInformer URL was retrievable. No PoC or exploit code found.
why Corroborates the absence of attribution and confirms observable phishing infrastructure; the inability to verify a direct DarkWebInformer URL means osint_chatter references are left empty rather than citing an unverified link.
- Does The Block add material context on the pre-disclosure exploitation window or Binance's involvement?Fetched The Block article.theblock.co ↗
Confirms all core facts; July 2026 Reddit and Trustpilot complaints document scammers already possessing name, address, phone, email, and order details—months before the August 2026 formal notification. Binance's role is that of an investor only; no operational Binance involvement in the breach.
why Pre-disclosure victim reports are the most significant evidential finding: they confirm the stolen data was actively weaponised at least three months before customers were warned, which is a material gap in SafePal's incident response timeline.
Research coverage
All 68 registered source leaves were evaluated for this run: 60 completed, 0 were unavailable, 1 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 59 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful — or not |
|---|---|---|---|
| BleepingComputernews | ok4 records | Primary evidence2 matched items | Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research. |
| AlienVault OTXdark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| CISA Alertsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| CISA KEVkev | ok1665 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5324 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok684 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1009 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| Exploit-DBexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| FIRST EPSSepss | ok7729 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok12 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Mastodon #infosecresearch | ok18 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok13 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok18 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| MISP threat actor galaxyactor | ok0 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| NVDcve | ok900 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| The Hacker Newsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Unit42 IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 5 opened outside the registered collection
Vendor & gov advisories1
Official vendor advisory confirming scope, affected data types, compounding retention error, remediation steps, and timeline.
Analysis & research4
Primary reporting; includes cybercrime forum listing details sourced from DarkWebInformer and phishing campaign timeline.
Independent corroboration; adds detail that SafePal has set a 90-day going-forward data-retention limit.
Further independent corroboration; notes fraudulent site safepal.support and confirmed pre-disclosure phishing activity.
Confirms July 2026 Reddit and Trustpilot complaints showing stolen data actively used months before formal customer notification.