Web3 wallet brand SafePal recently disclosed that a security vulnerability has been found in its order-tracking plugin, leading to unauthorized access to some customers’ information. The official statement says that additional security measures have been deployed to complete the fix.

According to the announcement, the incident affected approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. Exposed data includes sensitive fields such as names, email addresses, shipping addresses, phone numbers, and purchase details. All impacted customers have received separate notifications by email. SafePal has pledged to continue publicly sharing investigation progress.

Security incidents are especially sensitive for Web3 wallet projects, because users often link on-chain assets with personal information for custody. Recommended actions for affected users:

1. Watch out for phishing emails sent in the name of SafePal customer support, and do not click any suspicious links.
2. Check whether the same email and password combination was recently used on other platforms, and change it promptly.
3. Monitor further investigation updates from official channels, and if necessary, apply for credit monitoring services.

In recent years, plugin layers, third-party dependencies, and customer support systems have become the most common attack surfaces for Web3 projects. For any user holding crypto assets, once “off-chain data” such as order information is leaked, it can also evolve into an asset risk when combined with social engineering tactics. Self-custody on-chain does not automatically mean safety at the information level—privacy protection and key management are just as important.

#Web3安全 #钱包安全 #information security