Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ru發佈於 2026-08-17更新於 2026-08-17

文章摘要

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logisti...

The manufacturer of SafePal hardware crypto wallets has reported a data leak affecting approximately 39,798 users. The company disclosed the incident on August 16, clarifying that third parties gained access to customer names, delivery addresses, phone numbers, email addresses, and order information.

However, seed phrases, private keys, passwords, bank details, card numbers, and document numbers were not affected by the leak—SafePal initially does not collect or store such information. The project team has inspected its systems and found no signs that malicious actors gained access to user wallets or funds.

The Danger of the Leak for Customers

The developers warned: even without access to cryptocurrency assets, the leaked data provides grounds for targeted attacks. Scammers may call or write to customers posing as support staff, offer "refunds," persuade them to update device firmware, or send links to phishing resources impersonating the SafePal website.

The company is already tracking the appearance of such fake resources and working to get them blocked. Customers should be cautious of any communications that mention details of their orders—precisely this information may now be used to make messages appear credible.

Error in Order Tracking Plugin

According to SafePal, the leak occurred due to a vulnerability in the order tracking plugin linked to customer data. An authorization flaw in it allowed an unauthorized user to access orders of other customers—meaning they could see someone else's information where only their own should have been displayed.

By the time of the statement's publication, the developers had already fixed the issue and strengthened system protection measures. The incident affected those who placed orders between March 2, 2025, and April 11, 2026. When exactly the malicious actors exploited the vulnerability and when the project team discovered it was not specified by the company.

What SafePal is Doing Next

The manufacturer is currently investigating the incident in collaboration with an independent security company and preparing an audit of the entire order processing system. Among the measures taken are reducing the data retention period in the affected system to 90 days, notifying logistics partners with a request to check if the issue impacted their own systems, fixing the vulnerability in the plugin, and strengthening access controls to customer data.

Thus, the leak did not jeopardize the cryptocurrency assets of SafePal users, but it exposed enough personal data to organize fraudulent schemes through social engineering. The company states that it will continue to monitor the situation and investigate together with external security experts.

AI Opinion

Analysis reveals a clear industry pattern: the SafePal incident is already the third case of customer contact data leakage from hardware wallet manufacturers in recent years, and each time malicious actors use the same scheme—phishing emails sent impersonating support. A similar story happened with Ledger in 2020 when data of a million customers leaked, and victims were then pursued by fraudulent mailings for months, including fake devices by mail. Trezor faced the same problem very recently.

A technical aspect left outside the article's scope: the vulnerability arose not in the hardware wallet itself, but in a third-party order tracking plugin—this points to a weak link not in the devices' cryptography, but in auxiliary web services that companies connect to their platforms. Moreover, the leak's timeframe—over a year—raises questions: how many more such vulnerabilities in manufacturers' adjacent systems remain unnoticed until the data starts being used against the customers themselves?

熱門幣種推薦

相關問答

QAccording to the article, what type of user data was leaked in the SafePal incident?

AThe leaked data included customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive information like seed phrases, private keys, passwords, bank details, card numbers, and identification documents was not compromised, as SafePal does not collect or store such data.

QWhat is the primary security risk for SafePal customers following this data leak, as mentioned in the article?

AThe primary risk is targeted attacks using social engineering. Scammers can use the leaked personal and order information to impersonate SafePal support, call or message customers, offer 'refunds,' convince them to update device firmware, or send phishing links to fake websites, making their schemes appear more legitimate.

QWhat was identified as the specific cause of the data breach at SafePal?

AThe breach was caused by a vulnerability in an order tracking plugin. An authorization error in this plugin allowed unauthorized users to access the orders and personal information of other customers, seeing data that should only have been visible to the account owner.

QWhat period of time did the SafePal data breach affect, and what key actions did the company take in response?

AThe breach affected customers who placed orders between March 2, 2025, and April 11, 2026. In response, SafePal fixed the vulnerability, strengthened system protections, reduced data retention in the affected system to 90 days, notified logistics partners, initiated a full order system audit with an independent security firm, and is continuing its investigation with external experts.

QHow does the article's 'AI Opinion' section contextualize the SafePal incident within the hardware wallet industry?

AThe 'AI Opinion' notes this is the third such leak of customer contact data from hardware wallet companies in recent years, following similar incidents at Ledger (2020) and Trezor. It highlights a pattern where attackers use the data for phishing campaigns impersonating support. It also points out that the vulnerability was not in the cryptographic security of the hardware wallet itself, but in a third-party web service plugin, suggesting auxiliary systems are a weak link.

你可能也喜歡

Draper University为何在加速器实体项目中投入7万美元

德雷珀大学宣布启动Apex Growth Accelerator,这是一个为期10周的硅谷驻场计划,由德雷珀大学与Cardano基金会及Orion Fund合作推出,旨在加速早期Web3初创公司的成长。该计划为入选的、基于Cardano网络并已做好融资准备的团队提供高达7万美元的启动资金,换取3.5%的股权。申请截止日期为9月1日,核心驻场阶段将于10月12日在德雷珀大学圣马特奥校区开始。 该加速器重点关注快速增长的市场领域,特别是真实世界资产代币化、机构级去中心化金融以及企业级区块链基础设施。德雷珀大学旗下风险投资工作室Draper Dragon的负责人指出,行业已超越证明代币化可行的阶段,当前焦点在于在其基础上进行建设,下一波技术应用将发生在传统金融与DeFi的交汇处,加速器旨在投资这一转型。 尽管行业普遍转向全远程模式,德雷珀大学坚持要求创始人参加为期10周的现场核心驻场,并可选择延长4周。校方强调,现场环境能提供更高强度的互动、更快的决策速度和更深入的关系建立,这对于分布式团队至关重要。 该计划预计将孵化10家公司,并以面向Web3风投和机构投资者的演示日收官。但项目管理者强调,衡量成功的关键指标并非公司数量,而是创始人能否在项目结束后持续获得融资、吸引客户并实现业务增长。由于采用股权参与模式,该计划的目标是将创始人的成功与Cardano生态系统长期健康发展直接挂钩,旨在通过构建有价值的公司来提升生态系统的总锁仓价值和链上活动,形成良性循环。

cryptonews.ru10 分鐘前

Draper University为何在加速器实体项目中投入7万美元

cryptonews.ru10 分鐘前

您的账户仍未被冻结?俄罗斯联邦金融监管局将直接获取“快速支付系统”和“米尔卡”的数据权限

自2026年9月1日起,俄罗斯联邦金融监管局(Росфинмониторинг)将依据第461-ФЗ号联邦法律,有权直接从国家支付卡系统(НСПК)获取通过俄罗斯银行快速支付服务、统一支付码和“米尔”支付卡进行的交易信息。此举旨在扩展反洗钱系统的数据来源。 此前,监管机构需向各家银行单独查询以追踪资金链条,而新规实施后,可通过НСПК直接获取大部分支付路径信息,绕开单独的信贷机构。数据将通过个人账户或统一跨部门电子交互系统无偿提供,且查询无最低金额限制、不限于新法生效后的交易、无需客户同意或法院批准,同时禁止НСПК向客户透露信息已被提供。 具体交互程序将由金融监管局与НСПК在央行协调下另行协议确定,协议内容不公开,因此监管机构能获取的历史交易范围及是否允许批量查询目前尚不明确。法律并未引入新税种、自动冻结账户或其他强制措施,若发现涉嫌违反反洗钱法规的行为,后续调查将按现有程序进行,新法主要是提升了原始数据的获取速度。 这一变化主要影响以往通过单家银行难以追踪的跨卡、跨服务转账,使其在НСПК基础设施内呈现为统一视图。分析指出,监管机构与支付运营商建立直接通道虽减少了中间环节,但也创造了敏感信息的集中节点,其技术脆弱性风险高于单个银行。与欧盟近期加强监管权力的趋势类似,但俄罗斯模式的特点在于协议内容不公开且禁止通知客户,降低了机制对持卡人的透明度。该法律的适用范围是否会严格限于反洗钱控制,仍有待司法实践给出答案。

cryptonews.ru12 分鐘前

您的账户仍未被冻结?俄罗斯联邦金融监管局将直接获取“快速支付系统”和“米尔卡”的数据权限

cryptonews.ru12 分鐘前

交易

現貨

熱門文章

如何購買DATA

歡迎來到HTX.com!在這裡,購買DATA Network (DATA)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買DATA Network (DATA)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的DATA Network (DATA)購買DATA Network (DATA)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易DATA Network (DATA)在HTX的現貨市場輕鬆交易DATA Network (DATA)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

810 人學過發佈於 2026.07.01更新於 2026.07.01

如何購買DATA

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 DATA (DATA)幣價的意見。

活动图片