One-line brief

On August 16, 2026, SafePal disclosed that an authorization-control flaw in its order-tracking plugin allowed external unauthorized access to order data. Approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026 may have had their names, email addresses, phone numbers, delivery addresses and order details exposed. This was not a compromise of the hardware wallet, firmware, seed-phrase or private-key systems. It was a dual failure of authorization checks and data-lifecycle management in the e-commerce order environment. The immediate risk for affected users is targeted “firmware upgrade” phishing built from genuine order information.

1. Incident overview: the order environment was exposed, not the wallet-key system

SafePal confirmed that its order-tracking plugin contained an authorization-control defect. Under specific conditions, one user could access another customer's order information without authorization. The company confirmed external unauthorized access affecting approximately 39,798 customers, covering orders placed from March 2, 2025 through April 11, 2026. SafePal made a formal disclosure on X at 18:33 Beijing time on August 16, 2026 and sent individual notification emails to affected customers.

Key figures and milestones include approximately 39,798 affected customers; more than 30 scam websites and phishing links identified and taken down; a scheduled order-data cleanup task that stopped running because of a configuration error between September 2025 and April 2026; the first matching report received in early May 2026; and a full review and rebuild of the order-processing workflow beginning in July.

Three points are especially easy to misread. First, there is no evidence that the hardware wallet, firmware, seed phrases or private-key systems were breached: SafePal says its cold-storage and wallet systems are isolated from e-commerce servers and that it does not collect or store users' seed phrases or private keys. Second, 39,798 is a customer count, not a wallet, address or order count, and not a count of people whose assets were stolen. Third, March 2, 2025 to April 11, 2026 is the order-date range; it is not the duration of attacker access, and SafePal has not published the exact date of the first unauthorized access.

2. Attack and fund-flow chain

The diagram below summarizes the incident chain. Some links are third-party analysis or technical inference; the official notice remains authoritative.

Attack and fund-flow chain for the SafePal order-data breach
Figure 1 | Order-data authorization failure, PII exposure and the targeted-phishing path

3. Technical breakdown: where did the defect sit?

The popular headline that a “hardware-wallet maker was hacked” does not describe the confirmed facts. The breached component was a plugin on the e-commerce order side. The more dangerous consequence was that the exposed information identified people who had purchased crypto hardware, allowing attackers to prioritize likely asset holders.

3.1 Root cause: order queries lacked object-level authorization

SafePal's official wording is that, under specific conditions, one user could access another customer's order information without authorization. From a technical perspective, the behavior is consistent with a failed object-level authorization check (IDOR / BOLA): the interface may verify only that the requester is a logged-in user, not that the requested order belongs to that user. Changing an order identifier could then expose another record. It is like receiving a hotel key card that opens every room on the corridor: the lock checks that the card was issued by the hotel, but not the room number.

Important limits must be stated plainly. SafePal has not disclosed the plugin name or supplier, request endpoints or exploitation method, a CVE number, the batch-enumeration method, the exact start and end dates of the flaw or its exploitation, the number of queries made against each customer, access logs, or an independent audit result. The confirmed fact is an authorization flaw in the order-tracking plugin that enabled external unauthorized access; a more specific code-level claim would go beyond the evidence.

3.2 Second control failure: data-lifecycle management

SafePal found that a scheduled order-data cleanup task did not run normally from September 2025 through April 2026 because of a configuration error. The failed cleanup was not the direct cause of unauthorized access, but it left old order records in an accessible environment and allowed the affected range to reach back to March 2025. If the cleanup task had worked, both the attack surface and the number of affected people should have been smaller. The case therefore combines two failed controls: authorization and data retention.

3.3 Why “just change wallets” does not solve this risk

The exposed material was identity and address information, not a cryptographic secret. Replacing a seed phrase or device cannot recover a leaked name, phone number, address or purchase record. If only order information was exposed, there is no need to migrate every asset solely because of this plugin incident; SafePal says firmware, devices, seeds and private keys were not exposed through it. The upgrades that matter are identity-layer controls—passkeys or hardware keys for email, SIM protection, exchange withdrawal allowlists and anti-phishing codes—and a higher trust threshold for unsolicited communications.

4. Delta's forensic view: how to handle phishing theft derived from PII

When leaked PII is used to create phishing-led asset theft, Delta & Capital's practical focus normally includes the following:

Victim-address mapping: Start with the victim's multi-chain addresses associated with the SafePal wallet, reconstruct the assets and timing of any drain, and distinguish abused approvals from a voluntarily disclosed private key or seed phrase.

Fund-flow reconstruction: Trace outgoing transactions hop by hop, mark consolidation addresses, bridges, mixers and exchange routes, and avoid adding flash-loan-style temporary positions to actual loss.

Address-cluster analysis: Group receiving addresses, gas-funding addresses and consolidation addresses used in the same phishing campaign to assess whether a single criminal group operated the batch.

Phishing-infrastructure correlation: Cross-link domains, email headers, sender IPs, QR-code landing pages and receiving addresses to build an entity graph for the same 30-plus phishing sites.

Endpoint identification: Determine whether the funds reached a centralized exchange with identity requirements.

Compliance-grade evidence preservation: Turn the fund-flow timeline into a report that a platform or law-enforcement agency can act on, with evidence grades and confidence levels.

Delta & Capital must be candid about the response window. In scams that combine real order information with a fake firmware story, a user who enters a seed phrase can see assets transferred automatically within minutes. Cross-chain and mixer actions are highly scripted, so the tracing window is short. For most users, preventive controls are therefore far more valuable than post-incident recovery.

5. Action list for affected users

  • Treat order information as public. Verify orders independently and never click verification links in emails, text messages or private messages.
  • Treat every unsolicited contact as high risk. Calls, emails or letters about firmware upgrades, refunds, recalls, wallet migration or a legal investigation should be treated as scams. SafePal says it will not proactively call customers or send physical letters.
  • Do not connect or activate unexpected hardware devices, including “replacement” or “recall” devices that appear to arrive from an official source.
  • Harden the identity layer: enable a passkey or hardware security key for email; stop using SMS as an exchange's only second factor; set a transfer PIN or SIM protection with the carrier; enable exchange withdrawal allowlists and anti-phishing codes.
  • Preserve evidence: save suspicious email headers, phone numbers, domains, QR codes and payment addresses.
  • Warn people in the household not to disclose addresses, device models or asset information to unknown callers; contact local police if physical safety is a concern.
  • If a seed phrase or private key was entered on a suspicious page, use a trusted device and official application to generate a completely new seed phrase immediately, move remaining assets to the new wallet, do not import the old seed into the new device, check EVM approvals and Permit signatures chain by chain, preserve all evidence and contact official support.
  • Be extremely alert to secondary scams. Anyone who charges first and guarantees recovery is almost certainly trying to make the victim lose money again.

6. Industry lesson: PII itself is an attack surface

For users, this case shows that buying a hardware wallet is itself sensitive information. When a complete address, phone number and cold-wallet purchase record are bundled together, the person moves far higher on an attacker's priority list than a random target. The risk stretches from online phishing to physical safety, which no seed-backup strategy can cover.

For the industry, the lesson has three layers. First, peripheral systems and third-party plugins are a real weak point for wallet providers: a single authorization bypass in the commerce layer can cause practical harm even when the key system is well isolated. Second, retention time is attack surface. If the cleanup task had not failed, the affected population could have been materially smaller; data minimization and deletion at expiry should be treated as security controls, not compliance decoration. Third, disclosure quality determines whether users can protect themselves. Without the plugin supplier, a root-cause postmortem and an independent audit conclusion, users are forced into passive defense. The industry needs earlier notices with more technical granularity.

7. Key concepts

IDOR / BOLA (broken object-level authorization): An interface checks identity but not resource ownership, so an attacker can change an order number or similar identifier to read another person's data. It is one of the most common authorization failures in e-commerce and API environments.

PII (personally identifiable information): Names, phone numbers, email addresses and physical addresses that can identify a natural person. In a crypto context, pairing PII with a cold-wallet purchase can directly identify a potential asset holder.

Spear phishing: Targeted fraud that uses real order details, device models or amounts to appear credible. In this case it takes the form of a fake firmware-upgrade or batch-recall notice.

Data retention: A mechanism that defines how long data is kept and automatically deletes it at expiry. When it fails, old records with no business value remain exposed.

SIM swap: An attacker uses leaked identity information to impersonate the victim to a carrier, transfers the phone number and takes over SMS codes and accounts.

KYT (Know Your Transaction): Transaction-level anti-money-laundering controls that provide a basis for tracing and cooperation after illicit funds reach an endpoint.

8. Frequently asked questions

Q: Was the SafePal hardware wallet hacked? Were my seed phrase and private key leaked?
A: There is no evidence of that. SafePal says the accessed environment contained customer order data, not seed phrases, private keys, wallet passwords, bank accounts, payment-card numbers or identity-document numbers. It says the wallet and cold-storage systems are isolated from its e-commerce servers and that it does not collect or store seed phrases or private keys.

Q: What does 39,798 mean, and am I included?
A: It is approximately 39,798 customers—not wallets, addresses, orders or stolen-asset victims—whose order dates fall between March 2, 2025 and April 11, 2026.

Q: Why does the range reach back to March 2025?
A: The scheduled cleanup task failed because of a configuration error from September 2025 through April 2026, so old orders that should have been deleted remained in the order system.

Q: Someone claiming to be SafePal called and said my X1 has a firmware vulnerability. Is it genuine?
A: Treat it as a scam. Similar scams appeared as early as May 2026, and the caller may know a name, phone number, email, full address and order details. SafePal says it will not proactively call or send physical letters, and it has taken down more than 30 related phishing sites. Do not enter a seed phrase, scan a QR code or install “firmware” at the caller's direction.

Q: Do I need to replace my hardware wallet or move every asset immediately?
A: If only order information was exposed, do not replace the device or migrate assets solely for that reason. Prioritize email, SIM and exchange-account identity protections. If a seed phrase or private key was entered on a suspicious page, immediately generate a new seed phrase and move the remaining assets.

Q: Can stolen assets be recovered?
A: It depends on whether the funds remain traceable, reach an exchange with identity requirements, and receive cooperation from relevant platforms and legal processes. Preventive protection is far more important than post-incident recovery, and any “guaranteed recovery” claim should be treated as a warning sign.

Content support

This article was supported by Delta & Capital's blockchain-security and compliance research team, based in Hong Kong. Its work covers CEX/DEX account restriction, risk-control and freeze appeals; stolen-asset tracing and recovery support; blockchain data analysis and compliance technology research; transaction tracing and fund-flow analysis; on-chain forensics; KYT/AML real-time risk controls and address screening; KYT/SOW source-of-funds reconstruction; and cross-chain, multi-asset path reconstruction. The team also prepares on-chain evidence and technical support for police reports and judicial cooperation. This is public-interest education and does not promise or constitute recovery or unfreezing, nor does it replace legal procedure.

Risk and compliance notice

This article is security and anti-fraud education. It is not investment advice and does not guarantee recovery. Incident data comes from public reporting and may change as investigations develop. Virtual-asset activities in mainland China are not protected by law; readers should assess risks rationally. Anyone whose assets are stolen or whose funds are lost to fraud should report promptly to police and pursue lawful remedies, while remaining alert to secondary scams using the promise of recovery.