In July, the team began a full review and rebuild of the order-processing system. That work surfaced the authorization flaw in the plug-in's order-tracking function. Engineers patched it and layered on further controls, and an independent security firm is now validating the fix and auditing the wider system.
SafePal also found that the data breach reached further back than it should have. A configuration error had quietly broken a scheduled data-cleanup process between September 2025 and April 2026. Records that should have aged out stayed live, stretching exposure as far back as March 2025.
A Threat Actor Claims to Be Selling the Records
A seller on a cybercrime forum now claims to hold the stolen order data. The listing cites the same order window and roughly the same customer count that SafePal published about the data breach. That overlap lends the claim some weight without confirming it.
The seller also offers prospective buyers order IDs and shipping countries pulled from the trove. Those samples can go through the company's own exposure-checking page, which turns a customer safety tool into a proof-of-authenticity service for the sale. If the claims hold up, buyers can validate the goods before paying.
No one outside the forum has confirmed that the seller possesses the full dataset. Criminal marketplaces carry a steady volume of recycled and fabricated listings. Until someone independently examines a sample, the sale sits as an allegation.
Why Order Data Puts Wallet Owners at Risk
Phishing built on this material does not need to guess. An attacker can cite a real order number, the correct device model, and a genuine delivery address. Those details strip away most of the cues people rely on to spot a fake. Customers began reporting emails and calls impersonating SafePal in May, months before the data breach became public.
One reported message claimed the X1 hardware wallet carried a newly discovered vulnerability and demanded an urgent firmware update. The link to this incident remains unconfirmed, though the pretext fits the pattern closely. Any approach that ends with a user typing a seed phrase into a webpage achieves what the intrusion could not.
The physical dimension deserves attention too. Confirmed home addresses tied to confirmed crypto ownership support mail-based scams and counterfeit replacement devices arriving unannounced. In rare cases, they support direct coercion. The company has already taken down more than 30 fraudulent websites and phishing links.
What Affected Customers Should Do
SafePal published a verification page where customers can check their orders against the data breach, using an order number and a shipping country. The company also emailed every affected person on August 16. Anyone unsure about a message should verify it through that page rather than replying.
An affected order does not force a hardware replacement or a transfer of funds. The devices remain secure and the keys never left them. Anyone who entered a seed phrase after a suspicious call or website should treat that wallet as compromised. Move the assets to a new wallet on a trusted device.
Legitimate support staff never ask for recovery phrases. Typing the official web address manually beats following any link. An unexpected hardware delivery referencing a past purchase warrants suspicion.
Final Thoughts
Two failures compounded here. One authorization flaw in a plug-in opened the door. A broken retention job then kept fourteen months of order records sitting behind it. The company has closed both gaps, cut its retention window to 90 days, and purged affected personal data from active servers.
For customers, the exposure does not fade with the patch. Order details do not expire, and the people buying them can afford to be patient. SafePal has fixed the flaw, but the data breach will keep feeding phishing attempts for months. The only durable defence is a flat refusal to share wallet credentials with anyone who asks.