
The SafePal crypto wallet has confirmed a data leak linked to a flaw in order tracking, while reassuring about the security of funds.
SafePal, a crypto wallet backed by Binance, suffered a data leak affecting nearly 40,000 customers between March 2025 and April 2026 due to a flaw in its order tracking plugin.
AI-generated summary
SafePal suffered a data breach affecting nearly 40,000 customers following an authorization flaw in its order tracking plugin.
Safe intact, front door wide open. SafePal, the Binance-backed crypto wallet, confirmed on August 16 that it had suffered a data breach affecting nearly 40,000 customers. The brand thus joins a growing list, after the Trezor leak revealed a few months earlier. No question here of stolen private keys. The flaw comes from elsewhere, from these logistics subcontractors that even the best-armored portfolios must necessarily delegate.
SafePal: a flaw in order tracking, not in the wallet
The company identified an authorization flaw in its order tracking plugin: a customer could, without wanting or knowing it, view the data of another. As a result, around 39,798 customers who ordered between March 2025 and April 2026 had their name, email, delivery address, telephone number and details of their purchases leaked, according to The Block. No bank details, no card number, no identity document was leaked. And above all, neither private keys, nor seed phrases, nor user funds were affected. The fault lay elsewhere. Not in the trunk.
SafePal says it has fixed the problem and strengthened its controls. The company also took down more than 30 fake sites set up in the process to trap worried customers, and warned those affected by email. Everyone can check their status with their order number and country of delivery.
“Although your SafePal wallet, recovery phrase, and private keys are secure, we identified a vulnerability in the order tracking extension that allowed unauthorized access to the information of a subset of customers.”
SafePal – Source
The real danger begins now, not the day of escape
This is the paradox of this type of incident. The leak itself costs no one anything, but it arms phishing campaigns which can be costly. An email that knows your name, address, and SafePal purchase history is likely to sound authentic. SafePal, in its official press release of August 16, also alerted its users to this precise risk: beware of messages that request a recovery phrase under the pretext of a post-incident “security check”. No serious company asks for it, ever, under any circumstances.
SafePal, Trezor, Bits of Gold: same week, same weak link
This is not an isolated case. The same week, Israeli broker Bits of Gold announced a leak affecting 200,000 clients, via a third-party software provider already linked to the SafePal and Trezor incidents. Three wallets, three different brands, one thing in common: the breach never comes from the hardware or the protocol, but from a subcontractor somewhere in the chain. Manufacturers may shield the silicon, but they will still delegate their logistics and order tracking to third parties who do not have the same security standards.
AI outlook — possibilities, not facts
Phishing campaigns targeted against SafePal customers
Very likely · Within weeks

Matt Hougan de Bitwise prévoit une multiplication par 10 à 100 des transactions blockchain, portée par l'automatisation des agents IA qui effectuent des micro-paiements et des rééquilibrages de portefeuilles en continu, dépassant largement l'usage humain actuel.

La blockchain MANTRA Chain a suspendu l'intégralité de ses transactions et endpoints par mesure de précaution suite à un incident non identifié. Aucun délai de rétablissement n'est annoncé, ravivant les craintes liées à un précédent effondrement en 2025.

La Wyoming Stable Token Commission a migré l'infrastructure cross-chain de son stablecoin FRNT vers Chainlink CCIP, abandonnant LayerZero après un audit de sécurité ayant révélé des lacunes dans la transparence et les pratiques opérationnelles.

L'Ethereum Foundation a lancé Platåberget, un testnet public dédié à la mise à niveau Glamsterdam. Ce réseau, opérationnel depuis le 13 août, testera l'ePBS et l'exécution parallèle des transactions avant un hard fork programmé le 20 août 2026.

Le cybercriminel ZeroBytes revendique l'exfiltration de 43 Go de données de l'Éducation nationale couvrant plus de vingt ans. Le ministère confirme une intrusion en juillet mais conteste l'étendue de la fuite concernant les élèves et personnels.

Près de sept semaines après l'intrusion, le ministère de l'Économie confirme le vol des données fiscales de 678 000 particuliers et professionnels par un pirate informatique, faisant craindre de nouvelles attaques contre les détenteurs de cryptomonnaies.