SafePal Hardware Wallet Order‑Tracking Plug‑in Authorization Flaw Exposes ~40k Customer Records
What Happened — SafePal disclosed an authorization flaw in a third‑party order‑tracking plug‑in that unintentionally revealed the names, email addresses, shipping addresses, phone numbers, and purchase details of ≈ 39,798 customers. The company emailed each affected user on August 16 to notify them of the exposure.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a breach of SOC 2 CC6 (Confidentiality) and CC5 (Privacy) controls that continuous‑compliance programs are built to prevent and evidence.
- Demonstrating timely breach notification, root‑cause remediation, and updated data‑handling policies is essential evidence for a defensible SOC 2 audit.
- Verisq’s CookiePLUS capability can streamline consent records, DSAR workflows, and privacy‑impact documentation to satisfy both GDPR/CCPA and SOC 2 privacy requirements.
Who Is Affected – Crypto‑hardware wallet users (primarily retail investors) and any organization that stores or processes personal data through third‑party e‑commerce components.
Recommended Actions
- Map the exposure to SOC 2 CC6/CC5 controls and capture remediation steps as audit evidence.
- Conduct a privacy impact assessment (PIA) and update consent/notification procedures.
- Implement continuous monitoring of third‑party plug‑ins for authorization misconfigurations.
- Verify that all DSAR processes are documented and test them against SOC 2 audit criteria.
Source: The Hacker News
Technical Notes – The flaw stemmed from an insecure authorization check in the order‑tracking plug‑in, effectively a misconfiguration that allowed any authenticated user to view other customers’ order data. No CVE was assigned, but the vulnerability resides in the plug‑in’s access‑control logic. Source: same article