Cryptocurrency hardware wallet manufacturer SafePal disclosed a data breach resulting from an authorization flaw within an order-tracking software plugin active between March 2025 and April 2026. The vulnerability allowed unauthorized access to order delivery records belonging to 39,798 customers, exposing full names, shipping addresses, phone numbers, email addresses, and product purchase details. SafePal confirmed that private keys, seed phrases, wallet passwords, payment details, and government IDs were not exposed or impacted. SafePal patched the software plugin, implemented 90-day data retention limits on order processing logs, took down over 30 fraudulent phishing domains, and issued targeted warnings regarding social engineering and impersonation risks.