Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruPubblicato 2026-08-17Pubblicato ultima volta 2026-08-17

Introduzione

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Crypto di tendenza

Domande pertinenti

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

Letture associate

Google and Meta Called Out for Benchmark Gaming

Recently, analysis firm SemiAnalysis accused tech giants Google and Meta of "benchmark gaming" with their AI models Gemini 3.8 Flash and Muse Spark 1.3. The accusation stems from a dramatic performance drop between two versions of the Terminal-Bench evaluation for AI agents. On the older, public Terminal-Bench 2.1, Gemini 3.8 Flash scored 89.4, ranking second and beating GPT-6 Astra, while Muse Spark 1.3 scored 88.8. However, on the newly released, more secure Terminal-Bench 4.0, their scores plummeted to 19.1 and approximately 33.3 respectively, far behind competitors. SemiAnalysis argues this indicates "benchmark contamination," where companies train models not on the public test questions themselves, but on expensive, privately purchased training data specifically designed to mimic the benchmark's style. This has evolved into a lucrative industry, with specialized firms selling tailored training tasks for thousands to hundreds of thousands of dollars. The article specifically points to Datacurve, a company that both sells expert coding data and runs its own benchmark (DeepSWE), where the accused models also performed well. Meta's Chief AI Officer, Alexandr Wang, dismissed the claims as a "silly argument," pointing out similar performance drops for other models like GPT-5.6 Sol. He stated Meta never claimed Muse Spark 1.3 was as powerful as top-tier models, only that it offered better value. The report concludes that this is the inevitable fate of all high-quality public benchmarks—they become "gamed" over time. The proposed solution of private, high-quality benchmarks comes with a significant downside: it would erode public transparency, turning open rankings into marketing tools and leaving developers without a common, fair measure to compare AI models.

marsbit3 h fa

Google and Meta Called Out for Benchmark Gaming

marsbit3 h fa

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

Coinbase co-founder Fred Ehrsam is venturing into the oil fields of Venezuela, a surprising shift for a prominent figure in the digital asset space. Through his company Primavera Infinita, he recently secured a production contract for the Budare-Elotes block with Venezuela's state oil firm PDVSA. This move into a politically volatile, sanction-scarred country highlights a bet on high returns from its reopening under new leadership and shifting U.S. foreign policy. Ehrsam’s investment reflects a venture capital-style appetite for risk, targeting assets deeply discounted by political uncertainty. He is not alone; smaller, politically connected U.S. firms like Aspect Holdings and Hunt Oil are also entering, while established giants like ExxonMobil remain cautious due to past expropriations. To manage the complex, capital-intensive nature of oil, Ehrsam is assembling a professional team. This trend extends beyond Ehrsam. Other crypto wealth, like BitMEX's Arthur Hayes and Tether, is diversifying into traditional hard assets—energy, metals, and agriculture—seeking physical scarcity as a long-term anchor. Tether, for instance, took a controlling stake in agricultural giant Adecoagro. These moves signify crypto capital's evolving interest: not just tokenizing real-world assets (RWA), but directly acquiring and operating them. Ultimately, Ehrsam's gamble is less on oil geology and more on the duration of Venezuela's current political window. It underscores a broader narrative where digital-era wealth seeks stability and scale in the physical world's most traditional, immovable resources.

marsbit3 h fa

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

marsbit3 h fa

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

Title: Refuting the "Ethereum Abandoning ETH" Argument: What Does Paying Gas Without ETH Really Mean? The debate sparked by Vitalik Buterin's discussion of EIP-8141 (Frame Transactions), which suggests users could pay transaction fees without holding ETH, has led to extreme claims that ETH will lose its value. However, this perspective misunderstands the proposal. Currently, an Ethereum user initiating a transaction must also pay the network's Gas fee in ETH. EIP-8141 aims to decouple these actions. It allows a transaction to be split into separate "frames." A user could sign a transaction to, for example, send USDC, while a separate Paymaster account pays the required ETH Gas fee on their behalf. The user would then settle the cost with the Paymaster using USDC or another token. From the user's perspective, they pay in a stablecoin without interacting with ETH. Crucially, from the Ethereum protocol's perspective, the Gas is still paid in ETH; only the settlement layer between the user and Paymaster changes. This concept isn't entirely new; ERC-4337's Account Abstraction already allows similar Gas sponsorship. EIP-8141 seeks to integrate this capability more natively. The core goal is to drastically improve user experience by abstracting away the complexity of Gas, similar to how one pays with a credit card abroad without handling the local currency. It also enables atomic operations, like bundling token approval with a swap, which would revert together if the swap fails. Regarding ETH's value, the argument that "no ETH is needed" is incorrect. While users may not hold ETH, Paymasters and services must still acquire and spend ETH to pay network fees on the backend. The demand for ETH shifts from being distributed across millions of user wallets to being concentrated in the balances of these service providers. The key variable is whether this improved usability attracts significant new users and increases overall network activity. If it does, total ETH burned in fees could rise substantially. If it doesn't, the change merely reshuffles who holds the ETH needed for Gas. In summary, EIP-8141 aims to lower the entry barrier by hiding Gas complexity, betting that this will drive broader adoption and increase the fundamental utility—and thus demand—for the Ethereum network and ETH itself.

marsbit3 h fa

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

marsbit3 h fa

Trading

Spot

Articoli Popolari

Come comprare DATA

Benvenuto in HTX.com! Abbiamo reso l'acquisto di DATA Network (DATA) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente DATA NetworkDATA.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva DATA Network (DATA)Dopo aver acquistato DATA Network (DATA), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia DATA Network (DATA)Scambia facilmente DATA Network (DATA) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

754 Totale visualizzazioniPubblicato il 2026.07.01Aggiornato il 2026.07.01

Come comprare DATA

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di DATA DATA sono presentate come di seguito.

活动图片