Hardware Wallet Manufacturer SafePal Discloses Data Leak Affecting Nearly 40,000 Customers

cryptonews.ruPublicado em 2026-08-16Última atualização em 2026-08-16

Resumo

SafePal, a hardware wallet manufacturer, has disclosed a data breach affecting approximately 39,798 customers. The incident occurred between March 2, 2025, and April 11, 2026, due to an authorization flaw in an order-tracking plugin. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. The company emphasized that sensitive wallet credentials—such as seed phrases, private keys, and passwords—were not compromised. Bank account details, payment card numbers, and government IDs were also unaffected. The primary risk is now targeted phishing and scam attempts. Attackers may impersonate SafePal via emails, fake refund offers, fraudulent support channels, or malicious websites to steal user credentials. SafePal has patched the vulnerability, notified affected customers, and implemented enhanced security measures, including reducing personal data retention to 90 days and auditing order-processing systems. The firm advises users to never share their seed phrases or private keys, even if contacted by someone claiming to be from SafePal. While moving crypto assets is not necessary due to this breach, users who have already disclosed their credentials should consider their wallets compromised and transfer funds to a new, securely created wallet.

Hardware wallet manufacturer SafePal has reported a security incident that resulted in unauthorized access to order data for approximately 39,798 customers by third parties. The cause was an authorization error in the order tracking function associated with a related plugin. The incident could pose a risk of targeted phishing and fraud attacks against cryptocurrency wallet owners.

"We recently identified a flaw in the order tracking plugin that led to unauthorized access to information for a portion of customers," the company stated.

The incident affects users who placed orders between March 2, 2025, and April 11, 2026. Information that may have fallen into the hands of third parties includes name, email address, shipping address, phone number, as well as purchase and order details.

SafePal emphasized that seed phrases, private keys, passwords, and other wallet credentials were not compromised. The leak also did not involve bank account numbers, payment card numbers, or government-issued identity documents.

"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued documents," SafePal stated.

SafePal Fears Phishing Attacks

The company has already addressed the identified vulnerability and implemented additional security measures. Affected customers were notified by individual emails from security@safepal.com on August 16.

The primary risk following the leak is not the direct theft of cryptocurrency, but the potential use of the obtained information to carry out more convincing attacks.

Malicious actors may attempt to impersonate SafePal and contact users via:

  • email, phone calls, or SMS;
  • fake refund offers;
  • messages claiming firmware updates are needed;
  • fake customer support;
  • fraudulent websites and QR codes;
  • letters or physical parcels related to SafePal orders.

The company urged users never to share their seed phrase, private key, or password, even if the request appears to come from someone claiming to be a SafePal employee.

SafePal also reported that it has already taken down over 30 fraudulent websites and phishing links related to such activity and continues to monitor for new domains.

To check if a specific order was affected by the incident, the company published a separate page where users can enter their order number and shipping country.

Company Tightens Control Over Customer Data

SafePal stated that it is engaging an independent third-party cybersecurity firm to verify the fix and conduct a broader audit of its order processing systems.

Furthermore, the company has:

  • reduced the retention period for personal data in the relevant environment to 90 days, unless otherwise required by law;
  • created a dedicated support channel for affected customers;
  • initiated checks on third-party logistics and fulfillment partners' systems;
  • continued collecting user reports on fraudulent activity.

SafePal specifically noted that users do not need to move their crypto assets solely because their order data was exposed to third parties.

At the same time, if a wallet owner has already shared their seed phrase or private key in response to a suspicious message or via a fraudulent website, the company recommends considering that wallet compromised and moving the remaining assets to a new wallet created using a trusted device or the official SafePal app.

The incident comes amid a series of recent leaks affecting hardware crypto wallet users. In particular, following the hack of Trezor's logistics partner, 13,689 customers were put at risk of targeted phishing attacks, although the manufacturer's own systems and devices were also not compromised.

Previously, a large-scale attack on Coldcard also sparked significant reaction among Bitcoin holders: following the $100M+ incident, long-term holders moved approximately 210,000 BTC, marking one of the largest coin movements in this category in 2026.

Criptomoedas em alta

Perguntas relacionadas

QWhat was the cause of the recent data breach at hardware wallet manufacturer SafePal?

AThe data breach was caused by an authorization error in the order tracking function related to a specific plugin.

QWhat type of sensitive customer information was NOT compromised in the SafePal data breach?

ASeed phrases, private keys, wallet passwords, bank account details, payment card numbers, and government-issued identification documents were NOT compromised.

QWhat is the primary risk for customers following the SafePal data leak, according to the article?

AThe primary risk is not the direct theft of crypto assets, but the increased potential for more convincing targeted phishing and fraudulent attacks using the exposed customer information.

QWhat specific action did SafePal take to address the breach for affected users?

ASafePal notified affected customers individually via email from security@safepal.com, fixed the vulnerability, implemented additional security measures, and set up a dedicated support channel for impacted clients.

QWhat advice does SafePal give to users who have already shared their seed phrase or private key with a scammer?

ASafePal advises users who have already shared their seed phrase or private key to consider that wallet compromised and to move any remaining assets to a new wallet created via a trusted device or the official SafePal app.

Leituras Relacionadas

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

Roman Storm, founder of the cryptocurrency anonymization protocol Tornado Cash, convicted in August 2025 for conspiracy to operate an unlicensed money-transmitting business, has accused Google and OpenAI of facilitating North Korea's nuclear program. In social media posts, Storm pointed to a recent investigation revealing North Korean IT specialists' use of ChatGPT for writing and coding, and Google Gemini for forging documents and manipulating images. He argued that, under the same legal logic the U.S. Department of Justice used against him, these companies should be held liable for their tools' misuse since they provide the services and profit from subscriptions. Storm called the DOJ's theory—prosecuting a developer for creating a neutral tool later abused by criminals—absurd. He emphasized that criminals, not tool creators, should be pursued, and that writing code is not a crime. The Tornado Cash verdict sets a negative U.S. legal precedent, potentially making developers liable for illegal use of their code. Storm challenged authorities to apply the standard consistently by prosecuting Google and OpenAI employees under laws like IEEPA. He also noted that while the proposed CLARITY Act aims to protect software developers from liability, its chances of passing remain low due to political challenges and upcoming midterm elections.

cryptonews.ruHá 16m

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

cryptonews.ruHá 16m

Trading

Spot

Artigos em Destaque

Como comprar DATA

Bem-vindo à HTX.com!Tornámos a compra de DATA Network (DATA) simples e conveniente.Segue o nosso guia passo a passo para iniciar a tua jornada no mundo das criptos.Passo 1: cria a tua conta HTXUtiliza o teu e-mail ou número de telefone para te inscreveres numa conta gratuita na HTX.Desfruta de um processo de inscrição sem complicações e desbloqueia todas as funcionalidades.Obter a minha contaPasso 2: vai para Comprar Cripto e escolhe o teu método de pagamentoCartão de crédito/débito: usa o teu visa ou mastercard para comprar DATA Network (DATA) instantaneamente.Saldo: usa os fundos da tua conta HTX para transacionar sem problemas.Terceiros: adicionamos métodos de pagamento populares, como Google Pay e Apple Pay, para aumentar a conveniência.P2P: transaciona diretamente com outros utilizadores na HTX.Mercado de balcão (OTC): oferecemos serviços personalizados e taxas de câmbio competitivas para os traders.Passo 3: armazena teu DATA Network (DATA)Depois de comprar o teu DATA Network (DATA), armazena-o na tua conta HTX.Alternativamente, podes enviá-lo para outro lugar através de transferência blockchain ou usá-lo para transacionar outras criptomoedas.Passo 4: transaciona DATA Network (DATA)Transaciona facilmente DATA Network (DATA) no mercado à vista da HTX.Acede simplesmente à tua conta, seleciona o teu par de trading, executa as tuas transações e monitoriza em tempo real.Oferecemos uma experiência de fácil utilização tanto para principiantes como para traders experientes.

479 Visualizações TotaisPublicado em {updateTime}Atualizado em 2026.07.01

Como comprar DATA

Discussões

Bem-vindo à Comunidade HTX. Aqui, pode manter-se informado sobre os mais recentes desenvolvimentos da plataforma e obter acesso a análises profissionais de mercado. As opiniões dos utilizadores sobre o preço de DATA (DATA) são apresentadas abaixo.

活动图片