Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties
Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds.
The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information.
The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections.
In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logistics partners. While user crypto assets remain secure, the incident highlights a recurring pattern in the industry where breaches of customer data from hardware wallet companies lead to sophisticated phishing campaigns, similar to past incidents involving Ledger and Trezor. The vulnerability underscores that security risks often lie not in the wallet's cryptography but in auxiliary web services and third-party integrations.
cryptonews.ru17h ago