Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruPublicado a 2026-08-17Actualizado a 2026-08-17

Resumen

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Criptos en tendencia

Preguntas relacionadas

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

Lecturas Relacionadas

The End of Old Cryptography: How Ethereum is Preparing for the Era of Quantum Computing

Ethereum developers have proposed a new system for handling staking deposits, aiming to future-proof the network against the potential threat of quantum computers. Currently, Ethereum's security relies on elliptic curve cryptography, which could be broken by sufficiently powerful quantum machines capable of deriving private keys from public ones. While estimates of the timeline for this threat vary, with Google research in March 2026 suggesting it could be closer than previously thought, major blockchains are proactively preparing. The new proposal introduces a more flexible deposit contract capable of accepting keys of various types and lengths, identified by a scheme label. It also changes how deposit data is communicated within the network's layers. Crucially, the transition plan involves a three-phase process to ensure a controlled and predictable shift, initially disabling new deposits, then re-enabling the current format, and finally permanently switching to new post-quantum cryptography in a future update. The proposal is currently a draft with no set implementation date. It represents a strategic move to build infrastructure in advance, rather than a direct solution for existing accounts. Analysis notes that Ethereum is structurally vulnerable to a "store now, decrypt later" attack, as public keys revealed in past transactions remain permanently on-chain. This proposal prepares for a signature algorithm change but does not address the risk to keys already exposed.

cryptonews.ruHace 4 min(s)

The End of Old Cryptography: How Ethereum is Preparing for the Era of Quantum Computing

cryptonews.ruHace 4 min(s)

Meta Faces a $1.4 Trillion Penalty: Algorithmic Recommendation in the Dock. Will the Rules Change in the Second Half of the Internet Era?

A landmark federal trial in Oakland, California, has begun against Meta, with 29 states accusing the company of harming children and teens through its social media platform designs. The states seek a potential maximum penalty of $1.4 trillion, calculated from alleged repeated violations of consumer protection laws and the Children's Online Privacy Protection Act (COPPA) involving millions of underage users. The core legal strategy bypasses the traditional shield of Section 230 by targeting Meta's own platform features—like its recommendation algorithms, infinite scroll, and "like" buttons—rather than user-generated content. The plaintiffs argue these designs are addictive and deceptive. Meta denies the claims, calling the penalty "unprecedented" and disputing the methodology. While the astronomical $1.4 trillion figure is seen as a starting point for negotiations, even a significantly reduced penalty in the hundreds of billions could establish a critical precedent. The case focuses on holding platforms legally responsible for their algorithmic designs. A ruling against Meta could force product changes, such as removing "likes" or imposing usage limits, and provide a legal template for similar suits against other tech giants like TikTok and YouTube. The trial's outcome may redefine accountability for algorithm-driven business models across the internet.

marsbitHace 14 min(s)

Meta Faces a $1.4 Trillion Penalty: Algorithmic Recommendation in the Dock. Will the Rules Change in the Second Half of the Internet Era?

marsbitHace 14 min(s)

A Precedent for the Prediction Markets: CFTC Aims to Prove Authority Over Polymarket via Criminal Case

A U.S. Army soldier, Gannon Ken Van Dyke, who earned $400,000 using non-public information on the crypto event-prediction platform Polymarket, is contesting the U.S. Commodity Futures Trading Commission's (CFTC) attempt to intervene in his criminal case. The CFTC, which initiated a separate civil suit against Van Dyke but has not pursued it to trial, seeks to submit arguments in the ongoing criminal proceeding. Van Dyke's lawyers filed a motion opposing this, arguing the CFTC is improperly trying to influence the criminal case as an outside expert rather than through its own lawsuit. They contend that event contracts traded on platforms like Polymarket are not swaps and thus fall outside the CFTC's jurisdiction, calling the regulator's tactics a procedural maneuver. Van Dyke faces criminal fraud charges for allegedly trading based on confidential information about potential regime change in Venezuela. His civil case with the CFTC is stayed pending the criminal trial, expected in late 2026 or early 2027. The court's decision on whether to allow the CFTC's intervention could set a precedent for how such event contracts are regulated. An AI analysis notes inconsistency in the CFTC's approach compared to a similar case involving a Google employee, raising questions about the legal strategy for the prediction market industry, which includes platforms like Kalshi. The outcome may define future regulatory standards for the entire market.

cryptonews.ruHace 18 min(s)

A Precedent for the Prediction Markets: CFTC Aims to Prove Authority Over Polymarket via Criminal Case

cryptonews.ruHace 18 min(s)

Trading

Spot

Artículos destacados

Cómo comprar DATA

¡Bienvenido a HTX.com! Hemos hecho que comprar DATA Network (DATA) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar DATA Network (DATA) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu DATA Network (DATA)Después de comprar tu DATA Network (DATA), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear DATA Network (DATA)Tradear fácilmente con DATA Network (DATA) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

545 Vistas totalesPublicado en 2026.07.01Actualizado en 2026.07.01

Cómo comprar DATA

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de DATA (DATA).

活动图片