SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbitXuất bản vào 2026-08-17Cập nhật gần nhất vào 2026-08-17

Tóm tắt

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The in...

Written by: Xiao Bing

There is a counterintuitive rule in the field of crypto security: Knowing how much Bitcoin someone possesses is sometimes more dangerous than knowing their private key.

On August 16th, hardware wallet manufacturer SafePal issued a security bulletin confirming an authorization flaw in its order query plugin, which led to unauthorized access to the names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected customers placed orders between March 2, 2025, and April 11, 2026.

SafePal emphasized in the bulletin that private keys, seed phrases, wallet passwords, bank card numbers, and identity document information were not affected. The cold storage architecture operates in a completely isolated environment, separate from e-commerce servers. There is no evidence to suggest that user wallets or funds were directly compromised.

The company also disclosed that it has identified and taken down over 30 phishing websites related to this incident.

Why a Shopping List is More Frightening Than a Password

What the attackers now possess: The real names, mobile phone numbers, email addresses, and home addresses of nearly 40,000 individuals confirmed to have purchased hardware cold wallets.

The value of this data far exceeds that of typical e-commerce platform order leaks. People who buy cold wallets almost certainly hold crypto assets, and likely substantial amounts. Users willing to spend money on dedicated hardware to secure assets are typically not small-time investors holding just a few hundred dollars.

The attackers don't need to hack any device. What they can do includes:

Impersonating SafePal customer service, sending "firmware update notifications" or "device recall notices" containing real order numbers and purchase dates. Because the order information in the email is authentic, users are more likely to believe the entire email is genuine.

Sending physical letters or packages to the user's home address, including forged QR codes or "replacement devices." SafePal specifically warns in its bulletin to "treat any unexpected communications or hardware deliveries referencing SafePal purchase records as suspicious," indicating that such attacks have already occurred or are anticipated.

Cross-referencing leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to build more complete user profiles. Once it's confirmed that a resident at a particular address holds a significant amount of crypto assets, physical invasion (so-called "wrench attacks") becomes an option.

SafePal itself admits in its FAQ that phishing attacks may appear in various forms such as "phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer service communications." The length of this list itself speaks to the severity of the problem.

Three Months of Silence

What is most worth questioning in this incident is the disclosure timeline.

SafePal's FAQ page admits that it received user reports about phishing emails as early as May but initially treated them as "isolated incidents." A comprehensive review of the order system wasn't conducted until July, and the root cause wasn't confirmed and announced until August.

Approximately three months passed between the first report and the public disclosure. During these three months, attackers were already using the leaked data to send phishing emails, and SafePal confirmed it had discovered and taken down over 30 phishing websites. This means users were unknowingly exposed to highly targeted social engineering attacks for months.

SafePal also disclosed a detail: its data-purge routine had stopped running due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This implies the amount of leaked data might be larger than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.

The Security Paradox of Cold Wallets

This SafePal incident exposes a structural contradiction within the hardware wallet industry.

The entire selling point of a cold wallet is security. It protects private keys through physical isolation, preventing hackers from reaching core assets via cyber attacks. This promise, SafePal did fulfill; what leaked was the e-commerce system, not the wallet system.

But cold wallets must be sold through e-commerce channels, and these channels inherently require collecting users' real identity information: name, address, phone number, for logistics and delivery. Once this information is leaked, it precisely marks "who is safeguarding large crypto assets."

Ledger experienced an almost identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. Following the leak, victims reported numerous highly targeted phishing emails and SIM-swapping attacks. Some users even received death threats. Ledger's CEO later publicly apologized, acknowledging failures in the company's data retention and security practices.

SafePal now faces a replay of the same lesson. The only differences are the smaller scale (39.8k vs. 270k), but the attacker's playbook is exactly the same.

What Should You Do?

SafePal provided standard security advice in its bulletin: Do not share your seed phrase, do not click on unknown links, manually enter the official website address instead of clicking links in emails.

But for affected users, there are several more practical things worth doing.

The most urgent step is to check whether you have received any "firmware update" or "device recall" notifications sent in SafePal's name. If you have already entered your seed phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal clearly states in its bulletin that it will never ask for your seed phrase via phone, email, or any other channel.

Go to SafePal's dedicated verification page to check if you are affected using your order number. If confirmed, you can request deletion of your personal information. For the next several months, treat all physical letters and packages mentioning SafePal or cold wallets as suspicious. SafePal explicitly states it will never send physical letters.

If your shipping address is also where you store your crypto assets, seriously evaluate your physical security measures. This might sound like an overreaction, but after the Ledger leak, there were users who faced personal threats because of this very data.

The crypto industry has spent a decade educating users to "secure your private keys." The lessons from SafePal and Ledger show that attackers have long bypassed the private key; they target the person holding it. The moment the information "who is holding crypto assets" is leaked, even the most robust cold storage cannot offer protection.

The weakest link in the security chain has never been the chip or cryptography; it's the human.

Tiền kỹ thuật số thịnh hành

Câu hỏi Liên quan

QWhat is the central paradox exposed by the SafePal data leak regarding hardware wallet security?

AThe central paradox is that while hardware wallets physically isolate and securely protect private keys, making them immune to remote hacking, they must be sold through e-commerce channels that collect users' real personal information (name, address, phone, email). Leaking this e-commerce data precisely identifies and targets individuals who are likely holding significant crypto assets, shifting the attack vector from the digital key to the physical person holding it, bypassing the wallet's core security promise.

QWhat specific types of personal data were leaked in the SafePal incident, and during what period were the affected orders placed?

AThe leaked data includes the real names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected orders were placed between March 2, 2025, and April 11, 2026.

QAccording to the article, why is the leaked SafePal customer data considered more valuable than a typical e-commerce data breach?

AThis data is more valuable because it precisely identifies individuals who have purchased hardware cold wallets. Such a purchase strongly indicates that the individual holds cryptocurrency, likely in substantial amounts, as users willing to pay for dedicated security hardware are typically not small-scale holders. This makes the victims high-value targets for highly tailored social engineering and physical attacks.

QWhat critical failure in SafePal's data management practices contributed to the potential scale of this leak?

ASafePal disclosed that its data-purge routine, which was supposed to automatically delete old order information after 90 days as per its privacy policy, had stopped running due to a configuration error. This failure meant that a larger volume of customer data than intended remained in the system and was subsequently exposed in the breach.

QWhat is the primary practical security recommendation for affected users beyond the standard 'don't share your seed phrase' advice?

AThe article stresses that affected users should treat any unexpected physical mail or packages mentioning SafePal or hardware wallets as highly suspicious, as SafePal has explicitly stated it never sends physical letters. Additionally, if their shipping address is also where they store crypto assets, they should seriously evaluate their physical security measures, as the leaked data makes them potential targets for real-world threats like 'wrench attacks' or home invasions.

Nội dung Liên quan

Báo cáo Morgan Stanley giải thích: Không có hợp đồng dài hạn với bộ nhớ truyền thống chưa hẳn là xấu, DDR4 và SLC NAND đang trong chu kỳ tăng giá mạnh nhất

Báo cáo của Morgan Stanley (ngày 14/8) nhận định việc không có các thỏa thuận dài hạn (LTAs) định giá cố định trong lĩnh vực bộ nhớ truyền thống có thể là một lợi thế trong chu kỳ giá tăng hiện tại, cho phép các nhà sản xuất hưởng trọn lợi nhuận nhờ cơ chế giá giao ngay linh hoạt. Ba phân khúc chính đang có động lực tăng giá mạnh: 1. **DDR4:** Giá dự kiến tăng 50% vào Q3/2026 và hơn 10% vào Q4/2026, được hỗ trợ bởi nhu cầu từ cả máy chủ và điện tử tiêu dùng, trong khi nguồn cung thu hẹp do các nhà sản xuất lớn rút lui. 2. **SLC NAND:** Là sản phẩm có xác suất tăng giá cao nhất, dự báo tăng trên 50% trong cả Q3 và Q4/2026. Tình trạng thiếu hụt nguồn cung có thể kéo dài đến năm 2027, lâu hơn kỳ vọng thị trường. 3. **NOR Flash:** Sau các đợt tăng giá gần đây, dự kiến sẽ có thêm điều chỉnh tăng vào Q4/2026, với động lực kéo dài đến nửa đầu năm 2027 nhờ nhu cầu từ công nghiệp, ô tô, mạng và AI. Morgan Stanley điều chỉnh tăng mạnh dự báo lợi nhuận cho một số công ty, với mức ưu tiên: AP Memory (được chọn doanh nghiệp ưa thích hàng đầu) > GigaDevice > Macronix > Winbond > Powerchip > Nanya Tech. Động thái này phản ánh quan điểm cho rằng thị trường đang đánh giá thấp tính bền vững của chu kỳ tăng giá bộ nhớ truyền thống, nơi các nhà cung cấp nắm quyền định giá mạnh hơn trong bối cảnh thiếu hụt nguồn cung.

marsbit6 phút trước

Báo cáo Morgan Stanley giải thích: Không có hợp đồng dài hạn với bộ nhớ truyền thống chưa hẳn là xấu, DDR4 và SLC NAND đang trong chu kỳ tăng giá mạnh nhất

marsbit6 phút trước

Tiết Lộ Dòng Tiền 112 Tỷ USD Nửa Đầu Năm: Tài Sản Giá Trị Nhất Trong Ngành Mã Hóa Đang Chuyển Từ Code Thành Giấy Phép

Trong nửa đầu năm 2026, ngành công nghiệp tiền mã hóa đã huy động được 11,2 tỷ USD từ 377 vòng gọi vốn. Phân tích từ luật sư Irina Heaver và NeosLegal cho thấy một xu hướng rõ ràng: mọi khoản đầu tư công khai đều chảy vào các doanh nghiệp cần giấy phép quy định để hoạt động hợp pháp. Ba lĩnh vực dẫn đầu là Thanh toán & Stablecoin (3,7 tỷ USD), Thị trường Dự đoán (2 tỷ USD), và Sàn giao dịch (1,7 tỷ USD) - tất cả đều là những lĩnh vực phụ thuộc vào giấy phép. Các nhà đầu tư tổ chức như Sequoia, BlackRock, và Goldman Sachs đang định giá lại ngành: "giấy phép quy định đã từ một lưu ý tuân thủ trở thành một chỉ số định giá cốt lõi". Giấy phép (như MiCA hay VARA), với chi phí cao và thời gian xử lý dài, giờ đây tạo ra hàng rào cạnh tranh khó sao chép hơn nhiều so với mã nguồn. Điều này đánh dấu sự thay đổi logic đầu tư: từ cơ sở hạ tầng và giao thức (2020-2021) sang doanh nghiệp có doanh thu thực (2022-2023), và giờ là khả năng vận hành đổi mới trong khuôn khổ tuân thủ. Ngành tài chính truyền thống đã trải qua lộ trình tương tự. Tuy nhiên, có một sự phân tách: trong khi vốn tổ chức đổ vào các doanh nghiệp tập trung, có giấy phép, thì hoạt động của người dùng bán lẻ vẫn sôi động trên các giao thức phi tập trung, không cần giấy phép như Uniswap hay Aave. Tài sản giá trị nhất trong ngành đang được định nghĩa lại: từ một hợp đồng thông minh có thể sao chép sang một giấy phép hợp pháp có phạm vi hoạt động rộng. Thông điệp rõ ràng cho các nhà khởi nghiệp vào năm 2026: nếu muốn thu hút vốn tổ chức, trước tiên hãy có được giấy phép.

marsbit14 phút trước

Tiết Lộ Dòng Tiền 112 Tỷ USD Nửa Đầu Năm: Tài Sản Giá Trị Nhất Trong Ngành Mã Hóa Đang Chuyển Từ Code Thành Giấy Phép

marsbit14 phút trước

Hạ Tá Toàn, sắp thu hoạch IPO thứ năm

Thị trường A-shares sắp đón một công ty bán dẫn nổi bật mới: Đào Nham Bán Dẫn (Taurun Semiconductor), chuyên về chip kết nối tốc độ cao, vừa hoàn tất đăng ký hướng dẫn niêm yết tại Sở giao dịch chứng khoán Bắc Kinh, nhắm mục tiêu lên sàn ChiNext. Công ty được thành lập năm 2015 bởi Quản Dật, một chuyên gia kỳ cựu trong ngành chip với kinh nghiệm gần 20 năm. Ông trở về nước để nắm bắt cơ hội "thay thế hàng nội địa" trong lĩnh vực chip mô phỏng và chip hỗn hợp cao cấp. Đến nay, Đào Nham đã xây dựng bốn dòng sản phẩm chính phục vụ các ứng dụng như trạm gốc 5G, trung tâm dữ liệu AI và ô tô mới năng lượng. Điều đáng chú ý, từ năm 2018, công ty đã nhận được sự ủng hộ và đầu tư liên tục từ Hạ Tá Toàn - nhà đầu tư thiên thần huyền thoại, đồng sáng lập BYD. Thông qua công ty đầu tư Chính Huyên (Zhengxuan Capital), ông hiện nắm giữ 6.7% cổ phần của Đào Nham Bán Dẫn. Nếu IPO thành công, đây sẽ là lần IPO thứ 5 trong danh mục đầu tư của Hạ Tá Toàn, sau BYD, Youbixuan, Yutaimicro và Shangshui Intelligent. Tính đến nay, Đào Nham Bán Dẫn đã huy động được hơn 12 vòng tài trợ với tổng số tiền hơn 1 tỷ nhân dân tệ, thu hút nhiều tổ chức tên tuổi như Shenzhen Capital Group, Hillhouse Capital, cùng các quỹ vốn nhà nước địa phương và đặc biệt là sự tham gia của tập đoàn ô tô BYD. Doanh thu công ty được báo cáo tăng trưởng hơn 80% hàng năm từ 2022 đến 2024.

marsbit16 phút trước

Hạ Tá Toàn, sắp thu hoạch IPO thứ năm

marsbit16 phút trước

Bản trình bày bị giáo sư MIT chê là "vô lý" 5 năm trước, đã tiên tri tư duy cốt lõi của OpenAI o1 và o3

Năm năm trước, một báo cáo của nhà nghiên cứu Giambattista Parascandolo (hiện làm việc tại OpenAI) đã bị các giáo sư tại MIT chỉ trích là "vô nghĩa" trong buổi phỏng vấn xin việc. Báo cáo đó lại chứa đựng những ý tưởng tiên tri cho hướng phát triển của các mô hình suy luận như o1 và o3 sau này. Trong bài thuyết trình, Parascandolo đề xuất ba hướng nghiên cứu chính: 1. **Lập luận mở (Open-ended reasoning):** Mô hình có thể sử dụng nhiều thời gian và tính toán hơn để liên tục cải thiện câu trả lời, biến việc tính toán bổ sung thành kết quả tốt hơn - một ý tưởng tương tự "tính toán mở rộng khi suy luận" ngày nay. 2. **Sử dụng ngôn ngữ làm phương tiện suy luận:** Tận dụng kiến thức thế giới từ các mô hình ngôn ngữ lớn (như GPT) để mô tả môi trường, hiểu mục tiêu và lập kế hoạch, từ đó nâng cao hiệu quả trong các tác vụ như học tăng cường. Điều này gợi nhớ đến "chuỗi suy nghĩ" và quy trình làm việc của Agent hiện đại. 3. **Hệ thống AI có thể "thao túng" quá trình học của chính nó:** Agent có thể đặt lại tác vụ, tạo ra các kịch bản giả định, hay thậm chí đọc và sửa đổi các giá trị kích hoạt hoặc trọng số mạng nơ-ron của chính nó để luyện tập có chủ đích. Parascandolo cũng từng lập luận trong một bài blog năm 2021 rằng việc tiền huấn luyện quy mô lớn cho mạng nơ-ron có thể so sánh với quá trình tiến hóa trong sinh học, nén lượng kinh nghiệm khổng lồ để tạo ra khả năng học tập hiệu quả, chứ không nên so sánh trực tiếp với dữ liệu học ít ỏi của một đời người. Sau khi không nhận được vị trí tại MIT, Parascandolo gia nhập OpenAI. Anh đã tham gia phát triển GPT-4 và sau đó là các dự án nghiên cứu cốt lõi cho o1 và o3, biến những ý tưởng "vô nghĩa" ngày nào thành hiện thực.

marsbit17 phút trước

Bản trình bày bị giáo sư MIT chê là "vô lý" 5 năm trước, đã tiên tri tư duy cốt lõi của OpenAI o1 và o3

marsbit17 phút trước

Giao dịch

Giao ngay

Bài viết Nổi bật

Làm thế nào để Mua DATA

Chào mừng bạn đến với HTX.com! Chúng tôi đã làm cho mua DATA Network (DATA) trở nên đơn giản và thuận tiện. Làm theo hướng dẫn từng bước của chúng tôi để bắt đầu hành trình tiền kỹ thuật số của bạn.Bước 1: Tạo Tài khoản HTX của BạnSử dụng email hoặc số điện thoại của bạn để đăng ký tài khoản miễn phí trên HTX. Trải nghiệm hành trình đăng ký không rắc rối và mở khóa tất cả tính năng. Nhận Tài khoản của tôiBước 2: Truy cập Mua Crypto và Chọn Phương thức Thanh toán của BạnThẻ Tín dụng/Ghi nợ: Sử dụng Visa hoặc Mastercard của bạn để mua DATA Network (DATA) ngay lập tức.Số dư: Sử dụng tiền từ số dư tài khoản HTX của bạn để giao dịch liền mạch.Bên thứ ba: Chúng tôi đã thêm những phương thức thanh toán phổ biến như Google Pay và Apple Pay để nâng cao sự tiện lợi.P2P: Giao dịch trực tiếp với người dùng khác trên HTX.Thị trường mua bán phi tập trung (OTC): Chúng tôi cung cấp những dịch vụ được thiết kế riêng và tỷ giá hối đoái cạnh tranh cho nhà giao dịch.Bước 3: Lưu trữ DATA Network (DATA) của BạnSau khi mua DATA Network (DATA), lưu trữ trong tài khoản HTX của bạn. Ngoài ra, bạn có thể gửi đi nơi khác qua chuyển khoản blockchain hoặc sử dụng để giao dịch những tiền kỹ thuật số khác.Bước 4: Giao dịch DATA Network (DATA)Giao dịch DATA Network (DATA) dễ dàng trên thị trường giao ngay của HTX. Chỉ cần truy cập vào tài khoản của bạn, chọn cặp giao dịch, thực hiện giao dịch và theo dõi trong thời gian thực. Chúng tôi cung cấp trải nghiệm thân thiện với người dùng cho cả người mới bắt đầu và người giao dịch dày dạn kinh nghiệm.

Tổng lượt xem 630Xuất bản vào 2026.07.01Cập nhật vào 2026.07.01

Làm thế nào để Mua DATA

Thảo luận

Chào mừng đến với Cộng đồng HTX. Tại đây, bạn có thể được thông báo về những phát triển nền tảng mới nhất và có quyền truy cập vào thông tin chuyên sâu về thị trường. Ý kiến ​​của người dùng về giá của DATA (DATA) được trình bày dưới đây.

活动图片