
SafePal disclosed an authorization flaw in its order-tracking plugin that exposed personal order information of about 39,798 customers, including names, emails, shipping addresses, and phone numbers. Sensitive wallet data like seed phrases, private keys, and payment details were not compromised. The issue was discovered after a phishing report in May and confirmed in July, leading SafePal to fix the vulnerability and enhance security. The company has removed phishing sites, shortened data retention to 90 days, and is working with security experts to prevent future breaches.