Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ru2026-08-17 tarihinde yayınlandı2026-08-17 tarihinde güncellendi

Özet

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

Trend Kriptolar

İlgili Sorular

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

İlgili Okumalar

U.S. 'Operation Economic Outcast' Targets Iran's Crypto Sector, Over $100 Million in Oil-Related Payments Allegedly Facilitated via Cryptocurrency

U.S. Treasury Launches "Operation Economic Outcast," Sanctions Iran's Crypto Sector On August 24, the U.S. Treasury Department initiated "Operation Economic Outcast," a government-wide economic campaign against Iran. As part of this, the Office of Foreign Assets Control (OFAC) issued a sectoral sanctions determination targeting digital assets under Executive Order 13902, significantly expanding its authority. The Treasury stated that Iran is increasingly using cryptocurrency as a "tool of choice" to evade sanctions and support transactions linked to the Islamic Revolutionary Guard Corps (IRGC). Concurrently, OFAC sanctioned Ukrainian-Emirati broker Ivan Obukhov and his company, Foscom FZE. The Treasury alleges that since 2023, Obukhov has processed over $100 million in cryptocurrency payments to facilitate oil sales on behalf of the IRGC-Quds Force. Nearly 60 other entities, individuals, and vessels involved in nuclear procurement, cyber operations, and oil revenue networks were also sanctioned. This move marks an escalation from prior actions against specific exchanges, now establishing a broad basis to sanction any foreign entity deemed to operate in or support Iran's digital asset sector. Treasury Secretary Scott Bessent warned that any entity engaging economically with the Iranian regime will face the full reach of U.S. power, calling the operation an "economic D-Day" aimed at isolating Tehran.

marsbit9 dk önce

U.S. 'Operation Economic Outcast' Targets Iran's Crypto Sector, Over $100 Million in Oil-Related Payments Allegedly Facilitated via Cryptocurrency

marsbit9 dk önce

Is Your Account Still Blocked? Rosfinmonitoring Gets Direct Access to SBP and 'Mir'

Starting September 1, 2026, Russia's Federal Law No. 461-FZ grants Rosfinmonitoring (the Federal Financial Monitoring Service) direct access to transaction data from the National Payment Card System (NSPK), the operator of the Mir payment card system and the Faster Payments System (SBP). This allows the agency to bypass individual banks when reconstructing transaction trails for anti-money laundering (AML) purposes. The data, provided free of charge and without requiring customer consent or court orders, includes information on operations via SBP, the unified QR-code, and Mir cards, with no minimum transaction threshold. Customers will not be notified when their data is shared. The law does not introduce new taxes, automatic account freezes, or new enforcement powers. If suspicious activity is identified under existing AML laws, existing procedures with banks and law enforcement will apply. The agreement's specific terms between Rosfinmonitoring and NSPK, including the scope and historical depth of accessible data, are not public. The change centralizes access to a vast volume of domestic payments, potentially speeding up financial investigations. However, it also creates a single point of concentration for sensitive data and reduces transparency for cardholders, as customers are not informed about data requests. Observers note a global trend of expanding supervisory powers, with differences in the Russian model being the non-public agreement and the lack of customer notification.

cryptonews.ru12 dk önce

Is Your Account Still Blocked? Rosfinmonitoring Gets Direct Access to SBP and 'Mir'

cryptonews.ru12 dk önce

Solana Price Forecast Hits $110 as Bitwise's BSOL Posts Record Trading Volume

Solana (SOL) price is testing a critical resistance zone between $102-$103, having recently risen above $100 and now trading at $101.36. Technical analysis indicates a bullish but cautious trend, with the Parabolic SAR signaling a bullish short-term trend and the MACD gaining momentum. The price is within a rising wedge pattern, suggesting a potential breakout or sharper pullback. Key bullish factors include sustained, record-high network activity, with Solana processing over 1 billion transactions for the fourth consecutive week. Strong institutional demand is also evident, as Bitwise's Solana ETF (BSOL) recorded its highest-ever daily trading volume of over $108 million, contributing to significant daily inflows into SOL ETFs. However, caution is warranted. A major whale unstaked and transferred over 45,000 SOL, realizing a $3.3 million loss. Additionally, long-dated futures are trading at a discount to spot prices, indicating some long-term trader skepticism. **Price Forecast:** * **Bullish Case (Target: $110):** A confirmed daily close above the $102-$103 wedge resistance, supported by strong network usage and ETF inflows, could propel SOL towards $110. * **Bearish Risk (Support: $93-$95):** A rejection at resistance and a breakdown from the rising wedge's support could see the price retreat to the $93-$95 zone, especially if the whale's exit signals broader caution. In conclusion, the outlook is balanced between strong fundamental demand and emerging caution from large holders. The price action around the $102-$103 resistance will be decisive in determining the next significant move.

cryptonews.ru12 dk önce

Solana Price Forecast Hits $110 as Bitwise's BSOL Posts Record Trading Volume

cryptonews.ru12 dk önce

İşlemler

Spot

Popüler Makaleler

DATA Nasıl Satın Alınır

HTX.com’a hoş geldiniz! DATA Network (DATA) satın alma işlemlerini basit ve kullanışlı bir hâle getirdik. Adım adım açıkladığımız rehberimizi takip ederek kripto yolculuğunuza başlayın. 1. Adım: HTX Hesabınızı OluşturunHTX'te ücretsiz bir hesap açmak için e-posta adresinizi veya telefon numaranızı kullanın. Sorunsuzca kaydolun ve tüm özelliklerin kilidini açın. Hesabımı Aç2. Adım: Kripto Satın Al Bölümüne Gidin ve Ödeme Yönteminizi SeçinKredi/Banka Kartı: Visa veya Mastercard'ınızı kullanarak anında DATA Network (DATA) satın alın.Bakiye: Sorunsuz bir şekilde işlem yapmak için HTX hesap bakiyenizdeki fonları kullanın.Üçüncü Taraflar: Kullanımı kolaylaştırmak için Google Pay ve Apple Pay gibi popüler ödeme yöntemlerini ekledik.P2P: HTX'teki diğer kullanıcılarla doğrudan işlem yapın.Borsa Dışı (OTC): Yatırımcılar için kişiye özel hizmetler ve rekabetçi döviz kurları sunuyoruz.3. Adım: DATA Network (DATA) Varlıklarınızı SaklayınDATA Network (DATA) satın aldıktan sonra HTX hesabınızda saklayın. Alternatif olarak, blok zinciri transferi yoluyla başka bir yere gönderebilir veya diğer kripto para birimlerini takas etmek için kullanabilirsiniz.4. Adım: DATA Network (DATA) Varlıklarınızla İşlem YapınHTX'in spot piyasasında DATA Network (DATA) ile kolayca işlemler yapın.Hesabınıza erişin, işlem çiftinizi seçin, işlemlerinizi gerçekleştirin ve gerçek zamanlı olarak izleyin. Hem yeni başlayanlar hem de deneyimli yatırımcılar için kullanıcı dostu bir deneyim sunuyoruz.

559 Toplam GörüntülenmeYayınlanma 2026.07.01Güncellenme 2026.07.01

DATA Nasıl Satın Alınır

Tartışmalar

HTX Topluluğuna hoş geldiniz. Burada, en son platform gelişmeleri hakkında bilgi sahibi olabilir ve profesyonel piyasa görüşlerine erişebilirsiniz. Kullanıcıların DATA (DATA) fiyatı hakkındaki görüşleri aşağıda sunulmaktadır.

活动图片