Hardware Wallet Manufacturer SafePal Discloses Data Leak Affecting Nearly 40,000 Customers

cryptonews.ruОпубліковано о 2026-08-16Востаннє оновлено о 2026-08-16

Анотація

SafePal, a hardware wallet manufacturer, has disclosed a data breach affecting approximately 39,798 customers. The incident occurred between March 2, 2025, and April 11, 2026, due to an authorization flaw in an order-tracking plugin. Exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details. The company emphasized that sensitive wallet credentials—such as seed phrases, private keys, and passwords—were not compromised. Bank account details, payment card numbers, and government IDs were also unaffected. The primary risk is now targeted phishing and scam attempts. Attackers may impersonate SafePal via emails, fake refund offers, fraudulent support channels, or malicious websites to steal user credentials. SafePal has patched the vulnerability, notified affected customers, and implemented enhanced security measures, including reducing personal data retention to 90 days and auditing order-processing systems. The firm advises users to never share their seed phrases or private keys, even if contacted by someone claiming to be from SafePal. While moving crypto assets is not necessary due to this breach, users who have already disclosed their credentials should consider their wallets compromised and transfer funds to a new, securely created wallet.

Hardware wallet manufacturer SafePal has reported a security incident that resulted in unauthorized access to order data for approximately 39,798 customers by third parties. The cause was an authorization error in the order tracking function associated with a related plugin. The incident could pose a risk of targeted phishing and fraud attacks against cryptocurrency wallet owners.

"We recently identified a flaw in the order tracking plugin that led to unauthorized access to information for a portion of customers," the company stated.

The incident affects users who placed orders between March 2, 2025, and April 11, 2026. Information that may have fallen into the hands of third parties includes name, email address, shipping address, phone number, as well as purchase and order details.

SafePal emphasized that seed phrases, private keys, passwords, and other wallet credentials were not compromised. The leak also did not involve bank account numbers, payment card numbers, or government-issued identity documents.

"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued documents," SafePal stated.

SafePal Fears Phishing Attacks

The company has already addressed the identified vulnerability and implemented additional security measures. Affected customers were notified by individual emails from security@safepal.com on August 16.

The primary risk following the leak is not the direct theft of cryptocurrency, but the potential use of the obtained information to carry out more convincing attacks.

Malicious actors may attempt to impersonate SafePal and contact users via:

  • email, phone calls, or SMS;
  • fake refund offers;
  • messages claiming firmware updates are needed;
  • fake customer support;
  • fraudulent websites and QR codes;
  • letters or physical parcels related to SafePal orders.

The company urged users never to share their seed phrase, private key, or password, even if the request appears to come from someone claiming to be a SafePal employee.

SafePal also reported that it has already taken down over 30 fraudulent websites and phishing links related to such activity and continues to monitor for new domains.

To check if a specific order was affected by the incident, the company published a separate page where users can enter their order number and shipping country.

Company Tightens Control Over Customer Data

SafePal stated that it is engaging an independent third-party cybersecurity firm to verify the fix and conduct a broader audit of its order processing systems.

Furthermore, the company has:

  • reduced the retention period for personal data in the relevant environment to 90 days, unless otherwise required by law;
  • created a dedicated support channel for affected customers;
  • initiated checks on third-party logistics and fulfillment partners' systems;
  • continued collecting user reports on fraudulent activity.

SafePal specifically noted that users do not need to move their crypto assets solely because their order data was exposed to third parties.

At the same time, if a wallet owner has already shared their seed phrase or private key in response to a suspicious message or via a fraudulent website, the company recommends considering that wallet compromised and moving the remaining assets to a new wallet created using a trusted device or the official SafePal app.

The incident comes amid a series of recent leaks affecting hardware crypto wallet users. In particular, following the hack of Trezor's logistics partner, 13,689 customers were put at risk of targeted phishing attacks, although the manufacturer's own systems and devices were also not compromised.

Previously, a large-scale attack on Coldcard also sparked significant reaction among Bitcoin holders: following the $100M+ incident, long-term holders moved approximately 210,000 BTC, marking one of the largest coin movements in this category in 2026.

Трендові криптовалюти

Пов'язані питання

QWhat was the cause of the recent data breach at hardware wallet manufacturer SafePal?

AThe data breach was caused by an authorization error in the order tracking function related to a specific plugin.

QWhat type of sensitive customer information was NOT compromised in the SafePal data breach?

ASeed phrases, private keys, wallet passwords, bank account details, payment card numbers, and government-issued identification documents were NOT compromised.

QWhat is the primary risk for customers following the SafePal data leak, according to the article?

AThe primary risk is not the direct theft of crypto assets, but the increased potential for more convincing targeted phishing and fraudulent attacks using the exposed customer information.

QWhat specific action did SafePal take to address the breach for affected users?

ASafePal notified affected customers individually via email from security@safepal.com, fixed the vulnerability, implemented additional security measures, and set up a dedicated support channel for impacted clients.

QWhat advice does SafePal give to users who have already shared their seed phrase or private key with a scammer?

ASafePal advises users who have already shared their seed phrase or private key to consider that wallet compromised and to move any remaining assets to a new wallet created via a trusted device or the official SafePal app.

Пов'язані матеріали

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

Roman Storm, founder of the cryptocurrency anonymization protocol Tornado Cash, convicted in August 2025 for conspiracy to operate an unlicensed money-transmitting business, has accused Google and OpenAI of facilitating North Korea's nuclear program. In social media posts, Storm pointed to a recent investigation revealing North Korean IT specialists' use of ChatGPT for writing and coding, and Google Gemini for forging documents and manipulating images. He argued that, under the same legal logic the U.S. Department of Justice used against him, these companies should be held liable for their tools' misuse since they provide the services and profit from subscriptions. Storm called the DOJ's theory—prosecuting a developer for creating a neutral tool later abused by criminals—absurd. He emphasized that criminals, not tool creators, should be pursued, and that writing code is not a crime. The Tornado Cash verdict sets a negative U.S. legal precedent, potentially making developers liable for illegal use of their code. Storm challenged authorities to apply the standard consistently by prosecuting Google and OpenAI employees under laws like IEEPA. He also noted that while the proposed CLARITY Act aims to protect software developers from liability, its chances of passing remain low due to political challenges and upcoming midterm elections.

cryptonews.ru16 хв тому

Roman Storm Accuses Google and OpenAI in Connection with U.S. Department of Justice Ruling on Cryptocurrency Case

cryptonews.ru16 хв тому

Торгівля

Спот

Популярні статті

Як купити DATA

Ласкаво просимо до HTX.com! Ми зробили покупку DATA Network (DATA) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити DATA Network (DATA).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої DATA Network (DATA)Після придбання DATA Network (DATA) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля DATA Network (DATA)Легко торгуйте DATA Network (DATA) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

549 переглядів усьогоОпубліковано 2026.07.01Оновлено 2026.07.01

Як купити DATA

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни DATA (DATA).

活动图片