SafePal, a cryptocurrency hardware wallet manufacturer, disclosed a data exposure affecting nearly 40,000 customers through an authorization vulnerability in its order-tracking system.

The flaw exposed names, email addresses, shipping addresses, phone numbers, and purchase histories for approximately 39,798 customers. SafePal notified affected users via email on August 16 from security@safepal.com with the subject line "[Important] Your SafePal Order."

The vulnerability existed in an authorization mechanism within SafePal's order-tracking plug-in. Authorization flaws of this type typically allow attackers to bypass access controls and retrieve data intended to be restricted. In this case, the flaw permitted unauthorized access to customer records stored within the order management system.

The exposure carries particular risk for SafePal customers beyond standard identity theft concerns. Hardware wallet owners represent high-value targets for sophisticated attackers. Criminals now possess verified contact information, physical addresses, and purchase records showing that exposed individuals own cryptocurrency storage devices. This data combination enables targeted phishing campaigns, social engineering attacks, and potential physical theft attempts at customer residences.

The information exposed does not include private keys, seed phrases, or authentication credentials that would directly compromise wallet security. However, the shipping address and purchase data reveal where customers likely store their hardware wallets. Attackers can use this information to craft convincing pretexts for social engineering, impersonating SafePal support or delivery personnel.

SafePal manufactures hardware wallets designed to store cryptocurrency offline, protecting digital assets from online theft. The company markets its devices as security solutions for crypto holders. This breach demonstrates that security extends beyond the device itself to the companies operating supporting infrastructure like customer service systems and order tracking.

The vendor's response timeline remains unclear from available information. Security researchers and customers should verify when SafePal discovered the flaw, how long it remained exploitable, and whether attackers accessed the data before notification. These details determine the actual exposure window.

Organizations operating cryptocurrency infrastructure face regulatory scrutiny and customer trust requirements around data protection. This incident illustrates how even companies specializing in security products remain vulnerable to common web application flaws. Authorization bypass vulnerabilities ranked among OWASP's top security risks for over a decade, yet they continue affecting major vendors.

SafePal customers should monitor accounts for unauthorized access and phishing attempts. Financial institutions and email providers may flag communications from addresses claiming to be SafePal support as these now represent verified attack vectors. Customers who received the August 16 notification should treat unsolicited messages claiming to be from SafePal with heightened skepticism, particularly those requesting action or sensitive information.

The incident underscores the importance of security audits across all customer-facing systems, not only the core product. While SafePal's hardware wallets likely remain secure, the company's supporting infrastructure failed basic access control implementations. Customers relying on multiple layers of security should assume their physical location is now known to threat actors and adjust security practices accordingly.