SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbitPublicado a 2026-08-17Actualizado a 2026-08-17

Resumen

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The in...

Written by: Xiao Bing

There is a counterintuitive rule in the field of crypto security: Knowing how much Bitcoin someone possesses is sometimes more dangerous than knowing their private key.

On August 16th, hardware wallet manufacturer SafePal issued a security bulletin confirming an authorization flaw in its order query plugin, which led to unauthorized access to the names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected customers placed orders between March 2, 2025, and April 11, 2026.

SafePal emphasized in the bulletin that private keys, seed phrases, wallet passwords, bank card numbers, and identity document information were not affected. The cold storage architecture operates in a completely isolated environment, separate from e-commerce servers. There is no evidence to suggest that user wallets or funds were directly compromised.

The company also disclosed that it has identified and taken down over 30 phishing websites related to this incident.

Why a Shopping List is More Frightening Than a Password

What the attackers now possess: The real names, mobile phone numbers, email addresses, and home addresses of nearly 40,000 individuals confirmed to have purchased hardware cold wallets.

The value of this data far exceeds that of typical e-commerce platform order leaks. People who buy cold wallets almost certainly hold crypto assets, and likely substantial amounts. Users willing to spend money on dedicated hardware to secure assets are typically not small-time investors holding just a few hundred dollars.

The attackers don't need to hack any device. What they can do includes:

Impersonating SafePal customer service, sending "firmware update notifications" or "device recall notices" containing real order numbers and purchase dates. Because the order information in the email is authentic, users are more likely to believe the entire email is genuine.

Sending physical letters or packages to the user's home address, including forged QR codes or "replacement devices." SafePal specifically warns in its bulletin to "treat any unexpected communications or hardware deliveries referencing SafePal purchase records as suspicious," indicating that such attacks have already occurred or are anticipated.

Cross-referencing leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to build more complete user profiles. Once it's confirmed that a resident at a particular address holds a significant amount of crypto assets, physical invasion (so-called "wrench attacks") becomes an option.

SafePal itself admits in its FAQ that phishing attacks may appear in various forms such as "phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer service communications." The length of this list itself speaks to the severity of the problem.

Three Months of Silence

What is most worth questioning in this incident is the disclosure timeline.

SafePal's FAQ page admits that it received user reports about phishing emails as early as May but initially treated them as "isolated incidents." A comprehensive review of the order system wasn't conducted until July, and the root cause wasn't confirmed and announced until August.

Approximately three months passed between the first report and the public disclosure. During these three months, attackers were already using the leaked data to send phishing emails, and SafePal confirmed it had discovered and taken down over 30 phishing websites. This means users were unknowingly exposed to highly targeted social engineering attacks for months.

SafePal also disclosed a detail: its data-purge routine had stopped running due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This implies the amount of leaked data might be larger than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.

The Security Paradox of Cold Wallets

This SafePal incident exposes a structural contradiction within the hardware wallet industry.

The entire selling point of a cold wallet is security. It protects private keys through physical isolation, preventing hackers from reaching core assets via cyber attacks. This promise, SafePal did fulfill; what leaked was the e-commerce system, not the wallet system.

But cold wallets must be sold through e-commerce channels, and these channels inherently require collecting users' real identity information: name, address, phone number, for logistics and delivery. Once this information is leaked, it precisely marks "who is safeguarding large crypto assets."

Ledger experienced an almost identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. Following the leak, victims reported numerous highly targeted phishing emails and SIM-swapping attacks. Some users even received death threats. Ledger's CEO later publicly apologized, acknowledging failures in the company's data retention and security practices.

SafePal now faces a replay of the same lesson. The only differences are the smaller scale (39.8k vs. 270k), but the attacker's playbook is exactly the same.

What Should You Do?

SafePal provided standard security advice in its bulletin: Do not share your seed phrase, do not click on unknown links, manually enter the official website address instead of clicking links in emails.

But for affected users, there are several more practical things worth doing.

The most urgent step is to check whether you have received any "firmware update" or "device recall" notifications sent in SafePal's name. If you have already entered your seed phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal clearly states in its bulletin that it will never ask for your seed phrase via phone, email, or any other channel.

Go to SafePal's dedicated verification page to check if you are affected using your order number. If confirmed, you can request deletion of your personal information. For the next several months, treat all physical letters and packages mentioning SafePal or cold wallets as suspicious. SafePal explicitly states it will never send physical letters.

If your shipping address is also where you store your crypto assets, seriously evaluate your physical security measures. This might sound like an overreaction, but after the Ledger leak, there were users who faced personal threats because of this very data.

The crypto industry has spent a decade educating users to "secure your private keys." The lessons from SafePal and Ledger show that attackers have long bypassed the private key; they target the person holding it. The moment the information "who is holding crypto assets" is leaked, even the most robust cold storage cannot offer protection.

The weakest link in the security chain has never been the chip or cryptography; it's the human.

Criptos en tendencia

Preguntas relacionadas

QWhat is the central paradox exposed by the SafePal data leak regarding hardware wallet security?

AThe central paradox is that while hardware wallets physically isolate and securely protect private keys, making them immune to remote hacking, they must be sold through e-commerce channels that collect users' real personal information (name, address, phone, email). Leaking this e-commerce data precisely identifies and targets individuals who are likely holding significant crypto assets, shifting the attack vector from the digital key to the physical person holding it, bypassing the wallet's core security promise.

QWhat specific types of personal data were leaked in the SafePal incident, and during what period were the affected orders placed?

AThe leaked data includes the real names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected orders were placed between March 2, 2025, and April 11, 2026.

QAccording to the article, why is the leaked SafePal customer data considered more valuable than a typical e-commerce data breach?

AThis data is more valuable because it precisely identifies individuals who have purchased hardware cold wallets. Such a purchase strongly indicates that the individual holds cryptocurrency, likely in substantial amounts, as users willing to pay for dedicated security hardware are typically not small-scale holders. This makes the victims high-value targets for highly tailored social engineering and physical attacks.

QWhat critical failure in SafePal's data management practices contributed to the potential scale of this leak?

ASafePal disclosed that its data-purge routine, which was supposed to automatically delete old order information after 90 days as per its privacy policy, had stopped running due to a configuration error. This failure meant that a larger volume of customer data than intended remained in the system and was subsequently exposed in the breach.

QWhat is the primary practical security recommendation for affected users beyond the standard 'don't share your seed phrase' advice?

AThe article stresses that affected users should treat any unexpected physical mail or packages mentioning SafePal or hardware wallets as highly suspicious, as SafePal has explicitly stated it never sends physical letters. Additionally, if their shipping address is also where they store crypto assets, they should seriously evaluate their physical security measures, as the leaked data makes them potential targets for real-world threats like 'wrench attacks' or home invasions.

Lecturas Relacionadas

Claude's Watermark Has Been Cracked, Gaining 11k Stars, But Installation Is Refused

The article discusses the controversy surrounding Anthropic's implementation of a hidden watermark in all text generated by its AI, Claude. This policy, based on Google DeepMind's SynthID-Text technique, embeds a statistical signature by making inconsequential word choices. The watermark applies globally, even to human-written text lightly edited by Claude, sparking user backlash over issues of ownership and the creation of an "AI content second-class citizen" status. In response, an open-source tool called "watermarks-remover" (originally "remove-claude-marks") was released on GitHub, quickly gaining 11k stars. It works on three levels: removing invisible Unicode characters, using an agent to rewrite text and break statistical patterns, and stripping metadata from various file formats. Notably, Claude itself refused to install this removal tool as an Agent Skill, a task ultimately completed by another AI model, GLM 5.2. The article points out the irony that the removal code may have been written by Claude. The piece frames this as an ongoing battle between watermarking for traceability against misinformation and the desire for unmarked, owned content from paying users. It questions the practicality of mandatory technical markings when AI-generated text becomes indistinguishable from human writing, suggesting the open-source community's rapid development of countermeasures will continually outpace regulatory efforts.

marsbitHace 23 min(s)

Claude's Watermark Has Been Cracked, Gaining 11k Stars, But Installation Is Refused

marsbitHace 23 min(s)

30 Years After Being Crushed by AI, People Have Fallen Back in Love with Chess

On May 11, 1997, IBM's "Deep Blue" defeated chess champion Garry Kasparov, marking the first time a machine triumphed in a top-level intellectual game. The narrative of human defeat by AI seemed cemented when AlphaGo beat Lee Sedol in Go in 2016, a game once considered AI's final frontier. Yet, nearly 30 years after AI's dominance began, chess is experiencing unprecedented popularity. Chess.com boasts over 250 million registered users and 10 million daily active players. Its CEO, Erik Allebest, attributes this resurgence to several waves: the pandemic, the Netflix series *The Queen's Gambit*, and viral AI chess bots like "Mittens" on social media. Crucially, each surge left a permanently higher user base. The key insight is that AI liberated the game. When machines unequivocally became the best, the pressure to "win" as the ultimate human was removed. Chess returned to its core: the intrinsic joy of play—the thrill of a tactical combo, the tension of a time scramble, the curiosity of post-game analysis. AI, now serving as an always-available coach and anti-cheat tool, became infrastructure that enhanced rather than killed the experience. In contrast, Go, deeply rooted in East Asian elite culture and often pursued for mastery and status, suffered a "collapse of meaning" at the professional level after AlphaGo. Players began mimicking AI moves, erasing distinctive styles and narrative. While some Go players gained fame as online personalities, it didn't translate to widespread engagement with the game itself. The divergence highlights a fundamental question in the age of AI: is the motivation for an activity about *winning* or *playing*? Activities where the process itself is the reward, like chess, can thrive when the pressure of being the best is gone. AI may rightly take over tasks done purely for outcome, but it cannot replace the human experience of simply enjoying the game.

marsbitHace 59 min(s)

30 Years After Being Crushed by AI, People Have Fallen Back in Love with Chess

marsbitHace 59 min(s)

Exiting Top Ten Shareholders of Kweichow Moutai, 'Long-term Capital' Portfolio Adjustments Revealed: National Social Security Fund Enters 12 New Stocks, Invests in Hard Tech Mthreads

With the ongoing release of semi-annual reports, the second-quarter investment moves of long-term institutional investors like the National Social Security Fund (NSSF) and insurance capital are becoming clear. Central Huijin Asset Management and China Securities Finance Corp., often referred to as the "national team," are no longer among the top ten shareholders of Kweichow Moutai. Data shows that as of August 14th, the NSSF held positions in 33 A-share companies, with a total portfolio value exceeding 11 billion yuan. It added 12 new stocks in Q2, spanning sectors like chemicals, food & beverage, and semiconductors. The NSSF maintains its stable investment style, favoring companies with solid performance and attractive valuations. Apart from exiting Moutai, Huijin and China Securities Finance also left the top ten shareholder lists of companies like Ping An Bank and Dahua Technology. Insurance capital heavily invested in 41 companies in Q2, with a total holding value over 26 billion yuan. They showed a continued preference for cyclical sectors like non-ferrous metals and chemicals, as well as high-dividend-yield stocks. Analysts note that these long-term funds act as market stabilizers and investment bellwethers. Their presence is reshaping the market ecology, steering focus towards fundamental corporate value and away from speculative trading. A notable move was the NSSF's new investment in Moore Threads, a loss-making but leading domestic GPU design company listed on the STAR Market, indicating interest in hard technology sectors. Looking ahead, analysts expect long-term capital to continue a dual-strategy: maintaining a foundation in high-dividend-value stocks while gradually increasing exposure to growth areas aligned with industrial upgrading, such as advanced manufacturing and tech self-sufficiency. The market's recovery is seen as gaining a firmer footing after recent adjustments.

marsbitHace 1 hora(s)

Exiting Top Ten Shareholders of Kweichow Moutai, 'Long-term Capital' Portfolio Adjustments Revealed: National Social Security Fund Enters 12 New Stocks, Invests in Hard Tech Mthreads

marsbitHace 1 hora(s)

Data of 54,000 wallet users leaked, Clarity odds just 10%: Hodler’s Digest, Aug. 16

Galaxy Digital has slashed the odds of the CLARITY Act passing in 2026 from 75% to just 10%, citing limited Senate session days. If it fails, the SEC and CFTC plan to issue their own crypto rules, though an SEC meeting was abruptly cancelled. High-profile meetings at the White House are planned to discuss the bill. Amid growing hack fears, crypto companies are urging AI labs to grant developers early access to advanced AI models for cybersecurity, following a $116M Coldcard wallet theft. Data breaches at Trezor and SafePal have exposed over 54,000 users' personal information. The CFTC is clashing with states over regulating prediction markets like Kalshi, ordering it to ignore a New York restraining order to maintain a national market, while a Washington state judge ruled against it. The Ethereum Foundation is revising its post-quantum plan, moving away from the Poseidon hash function, and scoping its next major upgrade, Hegotá, for next year. Tether received its first full clean audit opinion from KPMG, showing reserves exceeding liabilities by $6.814 billion. Marketwise, major cryptos saw weekly declines. Predictions include a possible Bitcoin bottom in October, while analysts dispute the feasibility of BTC reaching $1M by 2030. Glassnode notes Bitcoin is in its longest capitulation phase since FTX's collapse. Three men were charged for an alleged Bitcoin kidnapping plot in Missouri.

cointelegraphHace 2 hora(s)

Data of 54,000 wallet users leaked, Clarity odds just 10%: Hodler’s Digest, Aug. 16

cointelegraphHace 2 hora(s)

50 Billion, Sichuan Brothers Have Struck It Rich

A new king of Sichuan stocks has emerged. This week, Chengdu Chaochun Applied Materials Co., Ltd. (Chaochun Yingcai) debuted on the ChiNext board, with its stock price surging over 700% intraday and its market value exceeding 50 billion yuan. Opening at 450 yuan per share, it surpassed New Easun to become the highest-priced stock in Sichuan's A-share market. This marks the success of a 21-year entrepreneurial journey by brothers Chai Jie and Chai Lin. Younger brother Chai Jie founded the company in 2005 in Chengdu, initially focusing on特种陶瓷. Elder brother Chai Lin, an expert in精密光学 and特种涂层, joined in 2008 to lead R&D. Facing a market monopolized by giants like KoMiCo and TOCALO, the company persisted. A breakthrough came in 2011 when its products entered the supply chain of AMEC (中微公司), a major domestic etching equipment maker. By 2020, its components reached the technical threshold for supporting 5nm process etching equipment. Revenue grew from 169 million yuan in 2023 to 496 million yuan in 2025, with semiconductor coating parts accounting for over 95% of sales. The IPO created significant wealth. The Chai brothers, holding a combined 46.88% stake, saw their paper wealth reach approximately 24 billion yuan. It also became the most profitable ChiNext IPO this year for retail investors. Employees benefited through two layers of持股平台, covering over 200 core technical and business staff. Early investors like SDIC Venture Capital, AMEC, and BYD (which invested 126.9 million yuan and now has a paper gain exceeding 1.8 billion yuan) also reaped substantial returns. The company represents a wave of tech leaders choosing to build their businesses in their hometown of Sichuan. Examples include New Easun in optoelectronics and Baili Tianheng in biopharmaceuticals. This trend shows that inland cities like Chengdu, with talent and industrial patience, can incubate specialized leaders that break foreign monopolies, offering an alternative model to the coastal hubs.

marsbitHace 2 hora(s)

50 Billion, Sichuan Brothers Have Struck It Rich

marsbitHace 2 hora(s)

Trading

Spot

Artículos destacados

Cómo comprar DATA

¡Bienvenido a HTX.com! Hemos hecho que comprar DATA Network (DATA) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar DATA Network (DATA) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu DATA Network (DATA)Después de comprar tu DATA Network (DATA), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear DATA Network (DATA)Tradear fácilmente con DATA Network (DATA) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

515 Vistas totalesPublicado en 2026.07.01Actualizado en 2026.07.01

Cómo comprar DATA

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de DATA (DATA).

活动图片