Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruPublicado em 2026-08-17Última atualização em 2026-08-17

Resumo

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Criptomoedas em alta

Perguntas relacionadas

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

Leituras Relacionadas

Tencent Reaps a Paper Profit of 50 Billion

A decade ago, China held no share in the global DRAM market. Today, Changxin Technology, after listing on the STAR Market, has become the most valuable A-share company. Its landmark IPO has generated historic returns for investors. Among them, Tencent, which invested approximately 2 billion RMB in 2022 through its entity Beijing Fengyi, now holds an estimated paper gain of around 50 billion RMB based on Changxin's current market valuation of approximately 4 trillion RMB. Alibaba also made significant bets. Its affiliates invested a total of roughly 7.6 billion RMB across two funding rounds in 2022 and 2025. Their combined stake is now worth an estimated 170 billion RMB—a paper profit surpassing Alibaba's entire net profit for fiscal year 2026. The shareholder registry reveals a who's who of Chinese capital. Major state-backed funds like the National Integrated Circuit Industry Investment Fund (Big Fund II) and Anhui provincial capital hold stakes worth hundreds of billions. Early and crucial support came from the Hefei municipal government, which played a foundational role in the company's establishment and growth. Strategic industrial investor GigaDevice, under the same leadership as Changxin, invested about 2.3 billion RMB, now worth roughly 53 billion. Home appliance giant Midea's 1 billion RMB investment has ballooned to an estimated 22 billion RMB. Virtually all major domestic financial institutions, venture capital, and private equity firms participated. However, the story also includes a notable exit: Country Garden's venture arm sold its stake for 2 billion RMB in late 2024 to address its own liquidity crisis. Those shares would be worth approximately 44 billion RMB at the IPO price, highlighting a stark contrast in timing between the downturn of the real estate cycle and the rise of the semiconductor sector.

marsbitHá 37m

Tencent Reaps a Paper Profit of 50 Billion

marsbitHá 37m

Calterah Races for the STAR Market: 31% Market Share, Over 900 Million in Losses, the Berkeley Mentor-Student Duo's Path to Breakthrough in Millimeter-Wave Radar

Calterah Microelectronics (Calterah), a Shanghai-based automotive chip company specializing in millimeter-wave radar chips, has filed for a listing on China's Sci-Tech Innovation Board (STAR Market), seeking to raise 3.49 billion yuan. Founded in 2014 by Dr. Chen Jiashu, a UC Berkeley PhD, and his professor Ali Niknejad, Calterah pioneered the use of CMOS technology for automotive-grade 77GHz radar chips, challenging the dominance of global giants like Texas Instruments. The company has grown rapidly, with revenue soaring from 206 million yuan in 2023 to 632 million yuan in 2025. It holds a 31.1% share in China's automotive millimeter-wave radar chip market and a 4% global share, with cumulative shipments exceeding 30 million chips for clients including BYD, Geely, NIO, Volvo, and Rivian. Despite strong market traction, Calterah faces significant financial challenges. It has reported cumulative net losses exceeding 900 million yuan over the past three and a half years, driven by massive R&D spending, which accounted for 147.75% of revenue in 2023. Operating cash flow remains negative, and the company relies heavily on external financing. Other risks include high customer and supplier concentration, with its top five distributors accounting for over 99% of revenue and overseas procurement exceeding 50%. Supply chain security is a concern due to reliance on foundries like TSMC. The proceeds from the IPO will fund R&D for high-performance radar chips, ultra-wideband (UWB) chips for applications like digital car keys, and a new technology center. Calterah aims to expand beyond automotive into industrial and consumer sectors. However, it faces intense competition, potential price wars, and the long, costly cycle of automotive-grade certification. Its path forward hinges on achieving profitability, maintaining technological leadership, and building a sustainable business model in a fiercely competitive global market.

marsbitHá 37m

Calterah Races for the STAR Market: 31% Market Share, Over 900 Million in Losses, the Berkeley Mentor-Student Duo's Path to Breakthrough in Millimeter-Wave Radar

marsbitHá 37m

Burning Through Billions, Market Cap Evaporates 200 Billion: SenseTime Suddenly Turns a Profit

Chinese AI giant SenseTime, once a star in the AI "Four Dragons," recently projected its first-ever profit for H1 2026, sparking a temporary stock surge. However, its current market cap of ~HK$64.6 billion remains over 80% below its peak of ~HK$300 billion in early 2022. The article analyzes SenseTime's dramatic fall from grace. It excelled in the "AI 1.0" era, dominating computer vision for applications like facial recognition and smart cities. However, it was disrupted by the "AI 2.0" generative AI revolution led by ChatGPT, which shifted focus from recognition to creation. Compounded by US sanctions, the death of its founder, a short-seller report, and a decline in its core smart city business, the company faced a perfect storm. Its workforce was cut by nearly 60%. To survive, SenseTime pivoted, actively "killing" its old self. It transitioned from project-based solutions to a generative AI and visual AI dual-engine model. Now, over 70% of its revenue comes from large language models, a more scalable, subscription-like business. Cost-control measures on expensive model training have also contributed to its path to profitability. Yet, significant challenges remain. The current AI race is an ecosystem battle dominated by giants like Microsoft/OpenAI, Google, and Chinese tech firms with integrated clouds, apps, and vast user bases. SenseTime, as an independent AI company, lacks such a super app or traffic gateway. The key question is whether it can build a sustainable moat based solely on model capability and industry deployment in this new competitive landscape.

marsbitHá 41m

Burning Through Billions, Market Cap Evaporates 200 Billion: SenseTime Suddenly Turns a Profit

marsbitHá 41m

Shanghai Sees a Semiconductor Equipment IPO Emerge, Led by Former Grace Semiconductor Employee

A Shanghai-based semiconductor equipment company, Mifee Technology, has filed for an IPO on the Shanghai Stock Exchange's STAR Market. The company specializes in developing and manufacturing Automatic Material Handling Systems (AMHS), a core automation system in semiconductor wafer fabrication that directly impacts production efficiency and yield. Mifee is one of the few domestic Chinese companies with proprietary AMHS technology, offering both hardware and software systems. While the global AMHS market is dominated by Japanese giants like Daifuku and Murata Machinery, which hold approximately 90% market share, Mifee has captured about 1.6% globally. The company's revenue has grown significantly, reaching 393 million yuan in 2025, and it achieved profitability that year with a net income of 60.45 million yuan, following losses in 2023 and 2024. Its revenue streams include sales of individual AMHS equipment and complete factory AMHS projects, with the latter starting to contribute revenue from 2024. The company faces risks including high customer concentration, with its top five clients accounting for over 90% of revenue in 2025, and significant fluctuations in gross margin, which was 48.97% in 2025 after dropping to 24.67% in 2024. Mifee is controlled by an 80s-born couple, Chairman/CEO Feng Miao and Deputy General Manager Na Ke, who previously worked at Shanghai Grace Semiconductor Manufacturing Co. The company plans to raise approximately 1.191 billion yuan from its IPO to fund production, R&D, overseas expansion, and working capital.

marsbitHá 42m

Shanghai Sees a Semiconductor Equipment IPO Emerge, Led by Former Grace Semiconductor Employee

marsbitHá 42m

Trading

Spot

Artigos em Destaque

Como comprar DATA

Bem-vindo à HTX.com!Tornámos a compra de DATA Network (DATA) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar DATA Network (DATA) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu DATA Network (DATA)Depois de comprar o teu DATA Network (DATA), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona DATA Network (DATA)Transaciona facilmente DATA Network (DATA) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

481 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.07.01

Como comprar DATA

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de DATA (DATA) são apresentadas abaixo.

活动图片