SafePal Leaks Data of Nearly 40,000 Hardware Wallet Buyers: Private Keys Intact, Yet Danger Moves Closer to the Physical

marsbitXuất bản vào 2026-08-17Cập nhật gần nhất vào 2026-08-17

Tóm tắt

Hardware wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2025 and April 2026. The leak exposed personal information including names, email addresses, phone numbers, physical delivery addresses, and purchase records. The company confirmed that private keys, recovery phrases, wallet passwords, and financial details were not compromised, as the cold storage systems operate in an isolated environment separate from the e-commerce servers. However, the breach poses significant risks beyond digital theft. Attackers now possess a high-value list of confirmed hardware wallet owners, effectively marking them as likely holders of substantial cryptocurrency. This enables highly targeted social engineering attacks, such as phishing emails referencing real order details, fake hardware deliveries, or phone scams impersonating SafePal support. The company has already identified and taken down over 30 related phishing sites. A critical aspect of the incident is the delayed disclosure timeline. SafePal acknowledged receiving initial user reports of phishing attempts in May but treated them as isolated. A full investigation began in July, with a public announcement not made until August, leaving users exposed for approximately three months. Furthermore, a configuration error prevented a data-purge routine from deleting old order information as intended, potentially increasing the scope of the leaked data. The in...

Written by: Xiao Bing

There is a counterintuitive rule in the field of crypto security: Knowing how much Bitcoin someone possesses is sometimes more dangerous than knowing their private key.

On August 16th, hardware wallet manufacturer SafePal issued a security bulletin confirming an authorization flaw in its order query plugin, which led to unauthorized access to the names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected customers placed orders between March 2, 2025, and April 11, 2026.

SafePal emphasized in the bulletin that private keys, seed phrases, wallet passwords, bank card numbers, and identity document information were not affected. The cold storage architecture operates in a completely isolated environment, separate from e-commerce servers. There is no evidence to suggest that user wallets or funds were directly compromised.

The company also disclosed that it has identified and taken down over 30 phishing websites related to this incident.

Why a Shopping List is More Frightening Than a Password

What the attackers now possess: The real names, mobile phone numbers, email addresses, and home addresses of nearly 40,000 individuals confirmed to have purchased hardware cold wallets.

The value of this data far exceeds that of typical e-commerce platform order leaks. People who buy cold wallets almost certainly hold crypto assets, and likely substantial amounts. Users willing to spend money on dedicated hardware to secure assets are typically not small-time investors holding just a few hundred dollars.

The attackers don't need to hack any device. What they can do includes:

Impersonating SafePal customer service, sending "firmware update notifications" or "device recall notices" containing real order numbers and purchase dates. Because the order information in the email is authentic, users are more likely to believe the entire email is genuine.

Sending physical letters or packages to the user's home address, including forged QR codes or "replacement devices." SafePal specifically warns in its bulletin to "treat any unexpected communications or hardware deliveries referencing SafePal purchase records as suspicious," indicating that such attacks have already occurred or are anticipated.

Cross-referencing leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to build more complete user profiles. Once it's confirmed that a resident at a particular address holds a significant amount of crypto assets, physical invasion (so-called "wrench attacks") becomes an option.

SafePal itself admits in its FAQ that phishing attacks may appear in various forms such as "phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer service communications." The length of this list itself speaks to the severity of the problem.

Three Months of Silence

What is most worth questioning in this incident is the disclosure timeline.

SafePal's FAQ page admits that it received user reports about phishing emails as early as May but initially treated them as "isolated incidents." A comprehensive review of the order system wasn't conducted until July, and the root cause wasn't confirmed and announced until August.

Approximately three months passed between the first report and the public disclosure. During these three months, attackers were already using the leaked data to send phishing emails, and SafePal confirmed it had discovered and taken down over 30 phishing websites. This means users were unknowingly exposed to highly targeted social engineering attacks for months.

SafePal also disclosed a detail: its data-purge routine had stopped running due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This implies the amount of leaked data might be larger than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.

The Security Paradox of Cold Wallets

This SafePal incident exposes a structural contradiction within the hardware wallet industry.

The entire selling point of a cold wallet is security. It protects private keys through physical isolation, preventing hackers from reaching core assets via cyber attacks. This promise, SafePal did fulfill; what leaked was the e-commerce system, not the wallet system.

But cold wallets must be sold through e-commerce channels, and these channels inherently require collecting users' real identity information: name, address, phone number, for logistics and delivery. Once this information is leaked, it precisely marks "who is safeguarding large crypto assets."

Ledger experienced an almost identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. Following the leak, victims reported numerous highly targeted phishing emails and SIM-swapping attacks. Some users even received death threats. Ledger's CEO later publicly apologized, acknowledging failures in the company's data retention and security practices.

SafePal now faces a replay of the same lesson. The only differences are the smaller scale (39.8k vs. 270k), but the attacker's playbook is exactly the same.

What Should You Do?

SafePal provided standard security advice in its bulletin: Do not share your seed phrase, do not click on unknown links, manually enter the official website address instead of clicking links in emails.

But for affected users, there are several more practical things worth doing.

The most urgent step is to check whether you have received any "firmware update" or "device recall" notifications sent in SafePal's name. If you have already entered your seed phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal clearly states in its bulletin that it will never ask for your seed phrase via phone, email, or any other channel.

Go to SafePal's dedicated verification page to check if you are affected using your order number. If confirmed, you can request deletion of your personal information. For the next several months, treat all physical letters and packages mentioning SafePal or cold wallets as suspicious. SafePal explicitly states it will never send physical letters.

If your shipping address is also where you store your crypto assets, seriously evaluate your physical security measures. This might sound like an overreaction, but after the Ledger leak, there were users who faced personal threats because of this very data.

The crypto industry has spent a decade educating users to "secure your private keys." The lessons from SafePal and Ledger show that attackers have long bypassed the private key; they target the person holding it. The moment the information "who is holding crypto assets" is leaked, even the most robust cold storage cannot offer protection.

The weakest link in the security chain has never been the chip or cryptography; it's the human.

Tiền kỹ thuật số thịnh hành

Câu hỏi Liên quan

QWhat is the central paradox exposed by the SafePal data leak regarding hardware wallet security?

AThe central paradox is that while hardware wallets physically isolate and securely protect private keys, making them immune to remote hacking, they must be sold through e-commerce channels that collect users' real personal information (name, address, phone, email). Leaking this e-commerce data precisely identifies and targets individuals who are likely holding significant crypto assets, shifting the attack vector from the digital key to the physical person holding it, bypassing the wallet's core security promise.

QWhat specific types of personal data were leaked in the SafePal incident, and during what period were the affected orders placed?

AThe leaked data includes the real names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected orders were placed between March 2, 2025, and April 11, 2026.

QAccording to the article, why is the leaked SafePal customer data considered more valuable than a typical e-commerce data breach?

AThis data is more valuable because it precisely identifies individuals who have purchased hardware cold wallets. Such a purchase strongly indicates that the individual holds cryptocurrency, likely in substantial amounts, as users willing to pay for dedicated security hardware are typically not small-scale holders. This makes the victims high-value targets for highly tailored social engineering and physical attacks.

QWhat critical failure in SafePal's data management practices contributed to the potential scale of this leak?

ASafePal disclosed that its data-purge routine, which was supposed to automatically delete old order information after 90 days as per its privacy policy, had stopped running due to a configuration error. This failure meant that a larger volume of customer data than intended remained in the system and was subsequently exposed in the breach.

QWhat is the primary practical security recommendation for affected users beyond the standard 'don't share your seed phrase' advice?

AThe article stresses that affected users should treat any unexpected physical mail or packages mentioning SafePal or hardware wallets as highly suspicious, as SafePal has explicitly stated it never sends physical letters. Additionally, if their shipping address is also where they store crypto assets, they should seriously evaluate their physical security measures, as the leaked data makes them potential targets for real-world threats like 'wrench attacks' or home invasions.

Nội dung Liên quan

Alexander Shokhin: Giới kinh doanh cần lãi suất dưới 10% và đồng đô la ở mức 90–95 rúp

Alexander Shokhin, Chủ tịch Liên minh Công nghiệp và Doanh nhân Nga (RSPP), cho rằng có thể sử dụng các công cụ "phi thị trường" để giữ đồng rúp trong một biên độ nhất định nhằm tránh biến động quá mức, dù ông thừa nhận đây là một chủ đề phức tạp cần thảo luận riêng. Ông Shokhin trước đó đã nhiều lần đề cập đến ý tưởng về một biên độ tỷ giá cho đồng rúp, lý do là thị trường ngoại hối hiện tại bị hạn chế về khối lượng và nhu cầu ngoại tệ giảm, khiến tỷ giá khó có thể coi là hoàn toàn theo cơ chế thị trường. Nhiều doanh nghiệp ủng hộ việc cố định biên độ, dù bằng các biện pháp không hoàn toàn thị trường, để tạo ra sự ổn định và dự báo được. Về các mục tiêu kinh tế, từ cuối năm 2025, Shokhin đã nêu ra những kỳ vọng của giới doanh nghiệp cho cuối năm 2026: lãi suất chính sách chính ở mức 12%, lạm phát trong khoảng 4-5% và tỷ giá USD/RUB ở mức 90-95. Tuy nhiên, ông cho biết mức lãi suất thực sự thoải mái cho hoạt động kinh doanh phải thấp hơn 10%. Ông nhấn mạnh tầm quan trọng của việc có một đồng tiền quốc gia ổn định và dự báo được đối với các quyết định đầu tư. Phân tích từ góc độ dữ liệu cho thấy, cơ chế biên độ tỷ giá không phải là mới đối với Nga. Cơ chế tương tự đã được áp dụng từ năm 1995 đến 1998, khi Ngân hàng Trung ương Nga (CBR) cố định tỷ giá USD trong một biên độ hẹp thông qua các can thiệp thường xuyên. Chế độ này kéo dài ba năm và sụp đổ sau cuộc khủng hoảng nợ tháng 8/1998, minh chứng cho tính mong manh của các mục tiêu cố định cứng nhắc khi đối mặt với các cú sốc bên ngoài. Mối liên hệ kinh tế vĩ mô ở đây rất rõ ràng: biên độ càng cứng nhắc thì càng cần nhiều dự trữ để bảo vệ nó khi đồng tiền chịu áp lực. Một khía cạnh kỹ thuật chưa được làm rõ là nguồn lực và quy mô can thiệp cụ thể trong điều kiện thanh khoản thị trường ngoại hối còn hạn chế. Liệu cuộc thảo luận hiện tại sẽ chỉ dừng lại ở lý thuyết hay sẽ chuyển thành các thông số biên độ cụ thể vẫn cần được theo dõi trong những tháng tới.

cryptonews.ru1 giờ trước

Alexander Shokhin: Giới kinh doanh cần lãi suất dưới 10% và đồng đô la ở mức 90–95 rúp

cryptonews.ru1 giờ trước

Chuyến tàu đến Bitcoin đã rời ga? Chỉ báo của người dùng không còn phát tín hiệu!

Giá Bitcoin tăng đã đưa chỉ báo AHR999, được các nhà đầu tư dài hạn theo dõi, ra khỏi vùng "mua khi đáy". Chỉ báo này đã trở lại phạm vi mua sắm bình thường sau khoảng 82 ngày. Theo dữ liệu từ các nguồn bên thứ ba, chỉ báo Ahr999 đạt mức 0,5073 sau đợt tăng giá gần đây của Bitcoin. Điều này đưa chỉ báo ra khỏi vùng "mua đáy" dưới 0,45 và chuyển nó vào vùng trung bình chi phí đô la (DCA) trong khoảng từ 0,45 đến 1,20. Trong chu kỳ hiện tại, khoảng thời gian chỉ báo Ahr999 duy trì dưới 0,45 bắt đầu từ ngày 29 tháng 5 và kết thúc vào ngày 19 tháng 8. Theo chỉ báo này, cửa sổ để mua Bitcoin ở mức thấp nhất kéo dài khoảng 82 ngày. Chỉ báo AHR999 đánh giá cả lợi nhuận ngắn hạn, ổn định từ việc mua Bitcoin và mức độ chênh lệch giữa giá hiện tại với định giá ước tính. Chỉ báo này đặc biệt hữu ích cho các nhà đầu tư sử dụng chiến lược mua dần dài hạn, giúp xác định các giai đoạn thị trường tương đối rẻ hoặc đắt. Theo lịch sử, chỉ số dưới 0,45 được hiểu là "mua khi đáy", trong khoảng 0,45 đến 1,20 là mua ổn định, và trên 1,20 là khu vực giá có thể tương đối cao. Tuy nhiên, bản thân chỉ báo này không được coi là tín hiệu mua hoặc bán rõ ràng. *Đây không phải là khuyến nghị đầu tư.

cryptonews.ru1 giờ trước

Chuyến tàu đến Bitcoin đã rời ga? Chỉ báo của người dùng không còn phát tín hiệu!

cryptonews.ru1 giờ trước

Vương quốc Bhutan chuyển 490 BTC trị giá 32,7 triệu USD sang các ví mới

Theo dữ liệu từ Onchain Lens, trong vòng 24 giờ qua, chính quyền Vương quốc Bhutan đã chuyển 490,87 Bitcoin, trị giá khoảng 32,74 triệu USD, sang các ví mới. Giao dịch lớn nhất là 485 BTC, tương đương gần 32,31 triệu USD, các giao dịch còn lại có giá trị nhỏ hơn. Trước đây, chính phủ Bhutan từng chuyển Bitcoin đến các địa chỉ không rõ hoặc ví liên quan đến các công ty giao dịch, nên mục đích thường khá rõ ràng. Tuy nhiên, lần này, các nhà phân tích chưa xác định được chủ sở hữu của các ví mới và cũng chưa thể khẳng định liệu các giao dịch này có liên quan đến việc bán coin hay không. Vào ngày 18 tháng 8, Vương quốc này đã chuyển 300 Bitcoin (trị giá 19,28 triệu USD) sang một địa chỉ khác để bán, tiếp tục làm giảm dự trữ tiền mã hóa hàng đầu của họ. Theo Arkham, vào tháng 10/2024, Bhutan nắm giữ hơn 13.000 BTC, nhưng đến tháng 3/2026, con số này chỉ còn 4.453 coin và đang tiếp tục giảm. Dự trữ Bitcoin quốc gia của Bhutan chủ yếu được tích lũy thông qua hoạt động khai thác (mining), nhờ nguồn điện giá rẻ từ các nhà máy thủy điện. Các giao dịch mới nhất diễn ra trong bối cảnh Bitcoin đang phục hồi, giao dịch quanh mức 77.600 USD tại thời điểm viết bài, tăng 7,8% trong ngày và 24% trong tuần theo số liệu từ CoinGecko.

cryptonews.ru3 giờ trước

Vương quốc Bhutan chuyển 490 BTC trị giá 32,7 triệu USD sang các ví mới

cryptonews.ru3 giờ trước

HYPE từ Hyperliquid vượt trội thị trường trong xu hướng giảm, giữa lúc AQAv2 chuẩn bị ra mắt

Mã token $HYPE của sàn phái sinh Hyperliquid được trader Pentosh1 đánh giá là "tài sản sinh lời nhất trong thị trường giảm", nhờ cơ chế phân phối doanh thu độc đáo. Gần như toàn bộ phí giao dịch từ thị trường phái sinh và spot được dùng để mua lại và đốt token $HYPE trên thị trường mở. Kể từ tháng 11/2024, 462 triệu token (trị giá ~1,27 tỷ USD) đã bị đốt, với khoảng 99% phí giao dịch dùng cho việc này. Một yếu tố thúc đẩy quan trọng khác là cơ chế AQAv2 (Aligned Quote Asset v2) dự kiến kích hoạt sau 6 ngày. Cơ chế này sẽ chuyển khoảng 90% thu nhập từ khoản dự trữ hơn 5 tỷ USD $USDC của nền tảng vào Quỹ Hỗ trợ Hyperliquid, ước tính tăng thêm 135-160 triệu USD cho hoạt động mua lại token hàng năm, bổ sung cho cơ chế hiện tại. Gần đây, giá $HYPE cũng biến động mạnh sau tuyên bố của cựu Tổng thống Donald Trump về nỗ lực hợp pháp hóa Hyperliquid tại Mỹ, khiến giá tăng 20-25% trong 24 giờ. Sự tăng trưởng của token được cho là dựa trên cơ chế mua lại và đốt token có khả năng mở rộng theo hoạt động giao dịch thực tế, thay vì phụ thuộc vào các chu kỳ hype thị trường.

cryptonews.ru3 giờ trước

HYPE từ Hyperliquid vượt trội thị trường trong xu hướng giảm, giữa lúc AQAv2 chuẩn bị ra mắt

cryptonews.ru3 giờ trước

Giao dịch

Giao ngay

Bài viết Nổi bật

Làm thế nào để Mua DATA

Chào mừng bạn đến với HTX.com! Chúng tôi đã làm cho mua DATA Network (DATA) trở nên đơn giản và thuận tiện. Làm theo hướng dẫn từng bước của chúng tôi để bắt đầu hành trình tiền kỹ thuật số của bạn.Bước 1: Tạo Tài khoản HTX của BạnSử dụng email hoặc số điện thoại của bạn để đăng ký tài khoản miễn phí trên HTX. Trải nghiệm hành trình đăng ký không rắc rối và mở khóa tất cả tính năng. Nhận Tài khoản của tôiBước 2: Truy cập Mua Crypto và Chọn Phương thức Thanh toán của BạnThẻ Tín dụng/Ghi nợ: Sử dụng Visa hoặc Mastercard của bạn để mua DATA Network (DATA) ngay lập tức.Số dư: Sử dụng tiền từ số dư tài khoản HTX của bạn để giao dịch liền mạch.Bên thứ ba: Chúng tôi đã thêm những phương thức thanh toán phổ biến như Google Pay và Apple Pay để nâng cao sự tiện lợi.P2P: Giao dịch trực tiếp với người dùng khác trên HTX.Thị trường mua bán phi tập trung (OTC): Chúng tôi cung cấp những dịch vụ được thiết kế riêng và tỷ giá hối đoái cạnh tranh cho nhà giao dịch.Bước 3: Lưu trữ DATA Network (DATA) của BạnSau khi mua DATA Network (DATA), lưu trữ trong tài khoản HTX của bạn. Ngoài ra, bạn có thể gửi đi nơi khác qua chuyển khoản blockchain hoặc sử dụng để giao dịch những tiền kỹ thuật số khác.Bước 4: Giao dịch DATA Network (DATA)Giao dịch DATA Network (DATA) dễ dàng trên thị trường giao ngay của HTX. Chỉ cần truy cập vào tài khoản của bạn, chọn cặp giao dịch, thực hiện giao dịch và theo dõi trong thời gian thực. Chúng tôi cung cấp trải nghiệm thân thiện với người dùng cho cả người mới bắt đầu và người giao dịch dày dạn kinh nghiệm.

Tổng lượt xem 641Xuất bản vào 2026.07.01Cập nhật vào 2026.07.01

Làm thế nào để Mua DATA

Thảo luận

Chào mừng đến với Cộng đồng HTX. Tại đây, bạn có thể được thông báo về những phát triển nền tảng mới nhất và có quyền truy cập vào thông tin chuyên sâu về thị trường. Ý kiến ​​của người dùng về giá của DATA (DATA) được trình bày dưới đây.

活动图片