The breach, caused by an "authorization flaw" in a plug-in, exposed names, physical addresses, and contact details for orders placed between March 2, 2025, and April 11, 2026. SafePal has patched the vulnerability and notified affected customers, stressing that core wallet security was not compromised, but warned of potential phishing and impersonation risks.