SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbitОпубліковано о 2026-08-17Востаннє оновлено о 2026-08-17

Анотація

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The in...

Written by: Xiao Bing

There is a counterintuitive rule in the field of crypto security: Knowing how much Bitcoin someone possesses is sometimes more dangerous than knowing their private key.

On August 16th, hardware wallet manufacturer SafePal issued a security bulletin confirming an authorization flaw in its order query plugin, which led to unauthorized access to the names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected customers placed orders between March 2, 2025, and April 11, 2026.

SafePal emphasized in the bulletin that private keys, seed phrases, wallet passwords, bank card numbers, and identity document information were not affected. The cold storage architecture operates in a completely isolated environment, separate from e-commerce servers. There is no evidence to suggest that user wallets or funds were directly compromised.

The company also disclosed that it has identified and taken down over 30 phishing websites related to this incident.

Why a Shopping List is More Frightening Than a Password

What the attackers now possess: The real names, mobile phone numbers, email addresses, and home addresses of nearly 40,000 individuals confirmed to have purchased hardware cold wallets.

The value of this data far exceeds that of typical e-commerce platform order leaks. People who buy cold wallets almost certainly hold crypto assets, and likely substantial amounts. Users willing to spend money on dedicated hardware to secure assets are typically not small-time investors holding just a few hundred dollars.

The attackers don't need to hack any device. What they can do includes:

Impersonating SafePal customer service, sending "firmware update notifications" or "device recall notices" containing real order numbers and purchase dates. Because the order information in the email is authentic, users are more likely to believe the entire email is genuine.

Sending physical letters or packages to the user's home address, including forged QR codes or "replacement devices." SafePal specifically warns in its bulletin to "treat any unexpected communications or hardware deliveries referencing SafePal purchase records as suspicious," indicating that such attacks have already occurred or are anticipated.

Cross-referencing leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to build more complete user profiles. Once it's confirmed that a resident at a particular address holds a significant amount of crypto assets, physical invasion (so-called "wrench attacks") becomes an option.

SafePal itself admits in its FAQ that phishing attacks may appear in various forms such as "phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer service communications." The length of this list itself speaks to the severity of the problem.

Three Months of Silence

What is most worth questioning in this incident is the disclosure timeline.

SafePal's FAQ page admits that it received user reports about phishing emails as early as May but initially treated them as "isolated incidents." A comprehensive review of the order system wasn't conducted until July, and the root cause wasn't confirmed and announced until August.

Approximately three months passed between the first report and the public disclosure. During these three months, attackers were already using the leaked data to send phishing emails, and SafePal confirmed it had discovered and taken down over 30 phishing websites. This means users were unknowingly exposed to highly targeted social engineering attacks for months.

SafePal also disclosed a detail: its data-purge routine had stopped running due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This implies the amount of leaked data might be larger than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.

The Security Paradox of Cold Wallets

This SafePal incident exposes a structural contradiction within the hardware wallet industry.

The entire selling point of a cold wallet is security. It protects private keys through physical isolation, preventing hackers from reaching core assets via cyber attacks. This promise, SafePal did fulfill; what leaked was the e-commerce system, not the wallet system.

But cold wallets must be sold through e-commerce channels, and these channels inherently require collecting users' real identity information: name, address, phone number, for logistics and delivery. Once this information is leaked, it precisely marks "who is safeguarding large crypto assets."

Ledger experienced an almost identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. Following the leak, victims reported numerous highly targeted phishing emails and SIM-swapping attacks. Some users even received death threats. Ledger's CEO later publicly apologized, acknowledging failures in the company's data retention and security practices.

SafePal now faces a replay of the same lesson. The only differences are the smaller scale (39.8k vs. 270k), but the attacker's playbook is exactly the same.

What Should You Do?

SafePal provided standard security advice in its bulletin: Do not share your seed phrase, do not click on unknown links, manually enter the official website address instead of clicking links in emails.

But for affected users, there are several more practical things worth doing.

The most urgent step is to check whether you have received any "firmware update" or "device recall" notifications sent in SafePal's name. If you have already entered your seed phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal clearly states in its bulletin that it will never ask for your seed phrase via phone, email, or any other channel.

Go to SafePal's dedicated verification page to check if you are affected using your order number. If confirmed, you can request deletion of your personal information. For the next several months, treat all physical letters and packages mentioning SafePal or cold wallets as suspicious. SafePal explicitly states it will never send physical letters.

If your shipping address is also where you store your crypto assets, seriously evaluate your physical security measures. This might sound like an overreaction, but after the Ledger leak, there were users who faced personal threats because of this very data.

The crypto industry has spent a decade educating users to "secure your private keys." The lessons from SafePal and Ledger show that attackers have long bypassed the private key; they target the person holding it. The moment the information "who is holding crypto assets" is leaked, even the most robust cold storage cannot offer protection.

The weakest link in the security chain has never been the chip or cryptography; it's the human.

Трендові криптовалюти

Пов'язані питання

QWhat is the central paradox exposed by the SafePal data leak regarding hardware wallet security?

AThe central paradox is that while hardware wallets physically isolate and securely protect private keys, making them immune to remote hacking, they must be sold through e-commerce channels that collect users' real personal information (name, address, phone, email). Leaking this e-commerce data precisely identifies and targets individuals who are likely holding significant crypto assets, shifting the attack vector from the digital key to the physical person holding it, bypassing the wallet's core security promise.

QWhat specific types of personal data were leaked in the SafePal incident, and during what period were the affected orders placed?

AThe leaked data includes the real names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected orders were placed between March 2, 2025, and April 11, 2026.

QAccording to the article, why is the leaked SafePal customer data considered more valuable than a typical e-commerce data breach?

AThis data is more valuable because it precisely identifies individuals who have purchased hardware cold wallets. Such a purchase strongly indicates that the individual holds cryptocurrency, likely in substantial amounts, as users willing to pay for dedicated security hardware are typically not small-scale holders. This makes the victims high-value targets for highly tailored social engineering and physical attacks.

QWhat critical failure in SafePal's data management practices contributed to the potential scale of this leak?

ASafePal disclosed that its data-purge routine, which was supposed to automatically delete old order information after 90 days as per its privacy policy, had stopped running due to a configuration error. This failure meant that a larger volume of customer data than intended remained in the system and was subsequently exposed in the breach.

QWhat is the primary practical security recommendation for affected users beyond the standard 'don't share your seed phrase' advice?

AThe article stresses that affected users should treat any unexpected physical mail or packages mentioning SafePal or hardware wallets as highly suspicious, as SafePal has explicitly stated it never sends physical letters. Additionally, if their shipping address is also where they store crypto assets, they should seriously evaluate their physical security measures, as the leaked data makes them potential targets for real-world threats like 'wrench attacks' or home invasions.

Пов'язані матеріали

Morgan Stanley Research Report Analysis: The Absence of Long-Term Agreements for Traditional Memory May Not Be Bad; DDR4 and SLC NAND Are in the Strongest Price Increase Cycle

Morgan Stanley's report on August 14, 2026, highlights a strong price upcycle in traditional memory chips, arguing that the absence of Long-Term Agreements (LTAs) is advantageous. The report focuses on three products where fundamentals are improving due to a widening supply-demand gap and increased pricing power: DDR4, SLC NAND, and NOR Flash. For DDR4, price hikes are forecasted at 50% in Q3 2026 and over 10% in Q4, driven by broad demand and accelerated supply exit. The lack of LTAs allows vendors to fully capture spot price gains. SLC NAND is identified as the highest-conviction call, with prices expected to surge over 50% in both Q3 and Q4 2026, supported by severe capacity constraints and demand migration from MLC. Supply tightness is projected to last into 2027. NOR Flash prices are also expected to rise further in Q4 2026, with momentum potentially extending into H1 2027, supported by industrial, automotive, and AI server demand. Morgan Stanley has raised earnings estimates for several companies, with AP Memory as the top pick, followed by GigaDevice, Macronix, Winbond, Powerchip, and Nanya Tech. The core thesis is that without LTAs, traditional memory suppliers have greater pricing flexibility to benefit from the current upcycle, which for DDR4 will last through H2 2026, and for SLC NAND and NOR Flash, potentially into H1 2027.

marsbit7 хв тому

Morgan Stanley Research Report Analysis: The Absence of Long-Term Agreements for Traditional Memory May Not Be Bad; DDR4 and SLC NAND Are in the Strongest Price Increase Cycle

marsbit7 хв тому

OpenAI Researcher Exposes ASI Timeline: Most Have Become Reality

In April 2025, a group of former OpenAI researchers published a 71-page document titled "AI 2027," outlining a timeline for Artificial Superintelligence (ASI). Their predictions, now being tracked by an independent project, show 51% are already confirmed, ahead of schedule, or on track. Notably, alarming predictions are arriving faster than anticipated. The forecast that AI would achieve top-tier human-level capabilities in cyber offense and defense by early 2027 was realized in April 2026, nine months early. Similarly, major Pentagon contracts with leading AI labs were signed 18 months earlier than predicted. The core mechanism for an intelligence explosion—Recursive Self-Improvement (RSI), where AI accelerates its own development—has not yet closed its loop. While AI, like Anthropic's Claude, now writes most new code, the bottleneck has shifted to human review and high-level research direction. A July 2026 study indicates the current AI-driven productivity gain in R&D is about 9%, below the estimated 15% threshold needed for a self-sustaining RSI feedback loop. However, underlying capabilities continue to accelerate rapidly. The "time horizon" metric for AI to autonomously handle tasks is doubling every three months, suggesting monthly-scale autonomous operation could be feasible by early 2027. Consequently, the original authors have revised their median prediction for fully automated AI programming forward to around mid-2028.

marsbit14 хв тому

OpenAI Researcher Exposes ASI Timeline: Most Have Become Reality

marsbit14 хв тому

Торгівля

Спот

Популярні статті

Як купити DATA

Ласкаво просимо до HTX.com! Ми зробили покупку DATA Network (DATA) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити DATA Network (DATA).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої DATA Network (DATA)Після придбання DATA Network (DATA) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля DATA Network (DATA)Легко торгуйте DATA Network (DATA) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

552 переглядів усьогоОпубліковано 2026.07.01Оновлено 2026.07.01

Як купити DATA

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни DATA (DATA).

活动图片