SafePal Official Twitter Discloses: Its Order Tracking Plugin Reportedly Has a Security Vulnerability, With 39,798 Customers’ Information Accessed Without Authorization Between March 2, 2025 and April 11, 2026.

The leaked data includes sensitive fields such as names, email addresses, shipping addresses, phone numbers, and purchase details, covering a fairly wide scope. At present, SafePal states that it has completed the fix by introducing additional security measures, and has sent separate email notifications to all affected users; the investigation is still ongoing.

From a user’s perspective, this incident again reminds us of several key points:

1. Third-party plugins are the attack surface in a wallet ecosystem that is easiest to overlook. Even if the main application is as tightly secured as possible, as long as a flaw exists in any part of the supply chain, user data could be leaked in bulk.

2. Even for non-custodial wallet brands, they often still need to maintain Web2 backend systems such as e-commerce, logistics, and order management—and these systems are also subject to traditional data security standards. If they are not properly managed, the damage is not only to brand reputation, but also to real compliance costs in terms of money.

3. After users receive the relevant notifications, they should immediately check for phishing risks. Attackers often conduct secondary scams using phrases such as “resend the order” and “security update.” Do not click links in unfamiliar emails.

Trust in the Web3 industry is built slowly, but can collapse in an instant. We hope more project teams will prioritize infrastructure security even further while pursuing functional iterations.

#SafePal #Web3安全 #privacy protection