Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info

摘要:SafePal disclosed a security breach that exposed names, physical addresses, and contact details of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The company attributed the incident to an authorization flaw in an order-tracking plug-in, which may have allowed attackers to view other customers' order details. It said no cryptocurrency funds, seed phrases, private keys, bank details, or government IDs were compromised, but warned affected users face heightened phishing and impersonation risks. SafePal said it has taken steps to address the situation. The disclosure follows a recent hack of Coldcard wallets, underscoring that no crypto-storage solution is entirely risk-free.

Summary

  • SafePal disclosed a security breach that exposed the names, physical addresses and contact details of 39,798 customers who placed orders between March 2, 2025, and April 11, 2026.
  • The company said no cryptocurrency funds, seed phrases, private keys, bank details or government IDs were compromised, but warned that exposed users face heightened phishing and impersonation risks.
  • SafePal has taken several steps to address the situation.

Crypto hardware wallet provider SafePal has disclosed a security incident that exposed the personal information of thousands of customers.

The exposed data included names, physical addresses, and contact details, putting affected users at risk of phishing and impersonation attempts. However, the breach did not compromise any cryptocurrency funds, passwords, or private wallet keys.

SafePal is a cryptocurrency security company that provides physical hardware wallets and software applications designed to help investors safely store and manage their digital assets.

The latest exploit follows a recent hack of Coldcard hardware wallets, in which the attacker reportedly stole at least $120 million in bitcoin. While the incidents do not necessarily point to a systemic weakness in hardware wallets, they show that no crypto-storage solution is entirely risk-free. They also validate calls to assess concentration risk and, where appropriate, to diversify both crypto holdings and the wallets used to store them.

What happened?

SafePal said on Sunday that it identified an “authorization flaw” in a plug-in used to track customer orders. This flaw likely allowed attackers to see other customers‘ orders. Think of it as a store’s parcel-tracking system allowing one customer to view another customers receipt and delivery details simply by changing the order number.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

CFTC 啟用緊急權力,確保 Kalshi 在紐約之爭中繼續營運

下一篇

幣安數據顯示,Z 世代青睞 ETF,交易頻率低於年長群體