Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ru發佈於 2026-08-17更新於 2026-08-17

文章摘要

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

熱門幣種推薦

相關問答

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

你可能也喜歡

Polymarket与Kalshi提供信号,但不保证预测结果

预测市场如Polymarket和Kalshi正成为投资者重要的信息来源。其核心优势在于参与者用真金白银下注,因此合约价格常被视为事件发生概率的市场评估。然而,这并非纯粹的概率,会受到流动性、手续费和参与者信息差异的影响。 关键问题在于:预测市场的高概率信号,是否意味着比特币等加密资产价格会跟随?答案是否定的。因为预测市场和加密货币市场解决的是不同问题:前者评估具体事件概率,后者直接进行资本分配和资产定价。 例如,预测市场显示美联储降息概率激增,这对加密投资者虽是重要信息,但降息预期可能已被提前计入资产价格。投资者可能已通过期货、期权调整了头寸。因此,预测市场的信号更多是衡量现有市场预期的另一种方式。 预测市场反映参与者认为可能发生的事,而加密市场则展示参与者已经用资金做出的实际行为。后者价格的形成还受仓位规模、杠杆、流动性及平仓需求等复杂因素驱动。 预测市场上有强烈看涨信号,并不直接构成比特币的交易信号。原因在于:其一,其背后的资金规模可能远小于加密市场的存量资本;其二,参与者可能仅为赚取概率变化的收益,而完全不交易标的资产;其三,专业交易者即使认同事件预测,也可能因认为价格已充分反映而进行反向操作。因此,正确预测事件并不保证资产价格会相应变动。 研究表明,预测市场在聚合信息和预测特定事件(如政治选举)方面往往优于传统民意调查。但将其价格直接等同于客观概率是错误的,其校准度受事件类别、时间跨度、交易规模和平台本身的影响。 总之,Polymarket和Kalshi提供的是一种有价值的补充信息,有助于洞察市场情绪和特定事件的预期概率,但不能将其信号简单等同于加密货币市场的直接价格指引。两者服务于不同目的,投资者需结合更广泛的市场结构和资金流数据做出决策。

cryptonews.ru16 分鐘前

Polymarket与Kalshi提供信号,但不保证预测结果

cryptonews.ru16 分鐘前

Glassnode:AI股上涨背景下消费者信心水平下滑,比特币落后

根据Glassnode的分析,尽管消费信心连续两个月略有改善,但仍处于近十年来的最低水平。消费者因预期生活成本上升和经济放缓,正将资金从现金转向资产,但关键问题在于资金流向。 美国股市在8月初创下历史新高,主要由人工智能相关股票驱动,而非广泛的市场普涨。比特币作为历史上被视为对冲传统金融体系风险的资产,并未参与这轮行情。数据显示,即使股市上涨,现货比特币ETF的资金却持续流出,表明资本正转向AI领域。 比特币目前价格仅为其2025年10月峰值的一半,在约63,000至68,700美元的狭窄区间内波动。与此同时,AI相关交易持续吸引散户、对冲基金乃至部分原比特币机构投资者的资金,他们正转向AI股票和AI概念的加密货币。 宏观环境理论上对比特币有利(如7月核心通胀率温和),但比特币对此反应冷淡,其现货交易量已降至2019年以来最低,ETF资金流入也大幅放缓。这暗示推动前两年上涨的机构购买力可能已暂停。 Glassnode指出,这种趋势不仅体现在交易流,比特币矿企也在将算力和电力合同转向AI工作负载。这像是一个结构性转变,可能持续削弱比特币作为“现金替代首选”的地位。但这并未否定比特币的抗贬值或稀缺性叙事,只是其积极影响未如市场预期在今年夏季显现。

cryptonews.ru18 分鐘前

Glassnode:AI股上涨背景下消费者信心水平下滑,比特币落后

cryptonews.ru18 分鐘前

交易

現貨

熱門文章

如何購買DATA

歡迎來到HTX.com!在這裡,購買DATA Network (DATA)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買DATA Network (DATA)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的DATA Network (DATA)購買DATA Network (DATA)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易DATA Network (DATA)在HTX的現貨市場輕鬆交易DATA Network (DATA)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

754 人學過發佈於 2026.07.01更新於 2026.07.01

如何購買DATA

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 DATA (DATA)幣價的意見。

活动图片