Loading article…
SafePal disclosed an authorization flaw that leaked order details of 39,798 users between March 2025 and April 2026, prompting phishing warnings and a 90‑day
SafePal announced on Aug 16 that an authorization defect in an order‑tracking plugin exposed the personal order information of 39,798 customers, raising immediate phishing risks while confirming that crypto assets, seed phrases and private keys remained untouched【1】.
| At a glance | |
|---|---|
| Affected users | 39,798 |
| Exposure window | Mar 2 2025 – Apr 11 2026 |
| Data leaked | Names, emails, shipping addresses, phone numbers, purchase details |
| Immediate response | Removed 30+ phishing sites; reduced data retention to 90 days |
The flaw allowed unauthorized parties to retrieve another customer’s order record by manipulating the order‑tracking plugin. SafePal first received a phishing report in early May, escalated the issue to a formal investigation in July, and confirmed the defect during a full review of its order‑processing pipeline later that month【1】. A separate configuration error halted a scheduled data‑cleanup between Sep 2025 and Apr 2026, extending the retention of older records and lengthening the exposure period【1】.
SafePal patched the vulnerability, added stricter access controls, and now limits personal‑data storage to 90 days, subject to legal requirements. The company removed more than 30 fraudulent websites linked to the breach and set up a dedicated support channel for affected users【1】. Although no wallet credentials or funds were compromised, the disclosed personal details could enable more convincing phishing attacks, prompting SafePal to advise any user who entered seed phrases on suspicious sites to treat the wallet as compromised and create a new one【1】.
The breach underscores that even hardware‑wallet providers are vulnerable to non‑wallet‑related attacks, shifting the risk focus toward data privacy and phishing defenses rather than direct asset theft.
Coverage is mostly measured — 184 of 190 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 16, 2026 · How we report
The goal is to make purchasing crypto easier by allowing users to utilize familiar local payment habits, such as mobile wallets or instant-payment systems, rather than relying on international rails.
The partnership provides merchants with the infrastructure to accept stablecoin payments, offering a fast and flexible way to transact using on-chain money while managing conversion and settlement.
No, ZeroHash accounts are not subject to FDIC or SIPC protections, or any equivalent protections that may exist outside of the United States.
Paybis supports over 20 local and international payment methods, including PIX, M-Pesa, Webpay, BLIK, SPEI, and MB WAY.