Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruPublished on 2026-08-17Last updated on 2026-08-17

Abstract

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Trending Cryptos

Related Questions

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

Related Reads

U.S. National Debt Approaches $40 Trillion in 5 Months, Bitcoin Debate Gains Momentum

The US national debt has surged to nearly $40 trillion in just five months, the fastest trillion-dollar increase on record. The debt's growth has accelerated dramatically over time, from taking 192 years to reach the first $1 trillion in 1981 to adding the latest $1 trillion in only five months. The federal budget deficit for the fiscal year is already over $1.8 trillion, exceeding last year's total, and net interest payments on the debt have surpassed $1 trillion, now exceeding defense or Medicare spending. This rapid debt accumulation is fueling arguments within the cryptocurrency industry that Bitcoin serves as a hedge against government-backed currencies and fiscal irresponsibility. Proponents, including some lawmakers and industry leaders, argue Bitcoin could act as a "hard currency" fiscal control mechanism. Legislation has even been proposed for the Treasury to acquire Bitcoin to help reduce the national debt. The International Monetary Fund has warned that global public debt could hit 100% of world GDP by 2029 if current trends continue, with the US and China as primary drivers. Some analyses suggest a sovereign debt crisis could drive capital into alternative assets like Bitcoin, similar to past regional banking crises. However, skeptics point out that both Bitcoin and gold have fallen in price at times during 2026 despite record debt, indicating the depreciation hedge theory may operate over a much longer timeframe than short-term price action.

cryptonews.ru8m ago

U.S. National Debt Approaches $40 Trillion in 5 Months, Bitcoin Debate Gains Momentum

cryptonews.ru8m ago

Technological Self-Reliance in China: A War from Lithography Machines to ABF Films

"China's Tech Independence: A Battle from Lithography Machines to ABF Film" In August 2026, Japan's Ajinomoto announced a 30% supply cut of ABF film to Chinese mainland clients, causing industry-wide shock and fears of price hikes and shortages in the semiconductor supply chain. That same year, Chinese company Lotus Holdings, known for its MSG business, acquired a small domestic ABF film startup for 103 million yuan, aiming to change this passive situation. ABF film is a core insulating material for advanced CPU, GPU, and AI chip packages. Ajinomoto, originally a food flavoring company, has monopolized over 95% of the global ABF film market for nearly 30 years, deriving its technology from byproducts of monosodium glutamate production. With AI chips consuming 5-10 times more ABF film than traditional chips, the supply-demand gap is widening. Ajinomoto's supply cut to China, where domestic ABF film production accounts for less than 5%, directly threatens the production of domestic high-end AI chips and their substrates. This incident highlights a crucial but often overlooked truth: the vulnerabilities in China's quest for technological self-reliance extend beyond headline areas like lithography machines to critical but seemingly minor components—insulating films, photoresists, electronic specialty gases, etc. The article frames China's tech independence as a multi-front war. While major breakthroughs have been achieved in chip design (e.g., Huawei's HiSilicon), foundry (e.g., SMIC), and memory chips (e.g., YMTC), countless smaller "Ajinomoto-style" chokepoints remain. Lotus Holdings' acquisition represents a significant shift: the battle is no longer fought only by tech giants but has become a collective, industry-wide effort involving companies from diverse backgrounds. Historically, external blockades have often spurred China's technological breakthroughs, as seen with Huawei's Kirin chips and YMTC's 3D NAND flash memory. Ajinomoto's supply cut, while a short-term challenge, may similarly catalyze domestic innovation in ABF film and other critical materials. The path to technological sovereignty is long and arduous, requiring sustained patience and investment to fill every gap in the complex supply chain. Lotus's move is not an immediate solution but a step towards that future, symbolizing a broader, relentless march toward independence.

marsbit28m ago

Technological Self-Reliance in China: A War from Lithography Machines to ABF Films

marsbit28m ago

The Great Ethereum "Rate Cut" Debate: Is Now the Golden Window for Staking with the Unconventional EIP-8363?

Ethereon's economic policy is under review as a new proposal, EIP-8363, sparks debate over potential "interest rate cuts" for staking. The unconventional proposal suggests gradually increasing the proportion of newly issued ETH rewards that are burned as the total staked ETH ratio rises, with issuance fully offset by burns once the ratio nears 50%. This would drive the protocol-level staking APR towards 0%, though validators would still earn transaction fees and MEV. This discussion emerges as staked ETH approaches 35% of supply, with the current protocol APR at ~2.6%. The core question is whether Ethereum needs to continue paying high issuance costs for marginal gains in security once sufficient participation is achieved. EIP-8363 aims to optimize security spending, but critics warn it could disproportionately impact solo stakers and potentially increase centralization among large, resilient operators. Paradoxically, this debate coincides with the Pectra upgrade (EIP-7251), which introduces native compounding for staking rewards, significantly improving capital efficiency for long-term holders. This creates a dual narrative: the protocol is making staking more efficient while reconsidering the economic incentive to stake. For long-term ETH holders, this environment may present a "time window" rather than a fixed-rate opportunity. While future APRs are expected to trend downward, starting staking earlier maximizes the compounding effect over time. The decision to stake depends on individual factors like investment horizon, liquidity needs, and risk tolerance regarding options like native validation, staking services, or liquid staking tokens (LSTs). The evolution from encouraging staking to managing its economic cost marks a new, mature phase for Ethereum's tokenomics, where the true value of staking may increasingly lie in the long-term power of compounding time.

marsbit36m ago

The Great Ethereum "Rate Cut" Debate: Is Now the Golden Window for Staking with the Unconventional EIP-8363?

marsbit36m ago

Analyst States Bitcoin Remains Within $61-68k Range

An analyst stated that Bitcoin is likely to remain within a trading range of $61,000 to $68,000. According to Kirill Komalenkov, director of strategic communications at Bitbanker, Bitcoin continues to trade sideways amidst declining market volatility. He attributes its current stability to high market liquidity, with volatility near three-year lows. Komalenkov warned that sustained low activity carries risks of a price decline, with potential tests of support at $62,300 and $61,600. He suggested that major market players might use the current situation to accumulate liquidity, meaning any initial breakout from the range could be a false move. The analyst expects this sideways movement to persist until the latter part of August. Key factors for determining future market direction include fund flows into Exchange-Traded Funds (ETFs) and trader activity. However, Komalenkov noted a potential negative scenario for the second half of August, where heightened geopolitical tensions or hawkish rhetoric from US monetary authorities could trigger a new decline. In such a case, Bitcoin could fall to a range of $45,000–$50,000 by early autumn, which might form a new base for a potential market recovery later in the season. Separately, a Russian deputy finance minister recently announced that non-qualified investors in Russia will soon be allowed to legally purchase Bitcoin, Ethereum, and popular stablecoins, with an annual limit of 300,000 rubles per intermediary.

cryptonews.ru38m ago

Analyst States Bitcoin Remains Within $61-68k Range

cryptonews.ru38m ago

Trading

Spot

Hot Articles

How to Buy DATA

Welcome to HTX.com! We've made purchasing DATA Network (DATA) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy DATA Network (DATA) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your DATA Network (DATA)After purchasing your DATA Network (DATA), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade DATA Network (DATA)Easily trade DATA Network (DATA) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

1.8k Total ViewsPublished 2026.07.01Updated 2026.07.01

How to Buy DATA

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of DATA (DATA) are presented below.

活动图片