SafePal has disclosed a data leak that potentially exposed the personal and purchase information of nearly 40,000 customers. The vulnerability in an order-tracking plugin affected orders placed between March 2025 and April 2026 and could have allowed unauthorised access to other customers’ order details. SafePal said there is no evidence that wallet access or customer funds were compromised. The company has fixed the flaw, added access controls and begun notifying affected users individually.

