ZCyberNews
中文
Industry NewsHigh3 min read

SafePal Breach Exposes Data of Nearly 40,000 Crypto Wallet Customers

SafePal confirms a breach affecting nearly 40,000 customers who ordered hardware wallets between March 2025 and April 2026, exposing names, emails, and addresses to phishing risks.

SafePal hardware wallet with a lock icon representing the data breach

Executive Summary

SafePal, a cryptocurrency hardware wallet manufacturer, confirmed on Sunday that a data breach compromised the personal information of nearly 40,000 customers. The stolen data includes names, email addresses, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. While SafePal insists that wallets, seed phrases, and private keys remain secure, the exposed personal data significantly increases the risk of targeted phishing and physical attacks against cryptocurrency holders.

This incident marks the third breach of a hardware wallet vendor in the past month, following similar incidents at Trezor and Coinkite. The recurrence highlights a growing threat to the ecosystem that relies on hardware wallets for secure storage of digital assets.

Technical Analysis

SafePal attributed the breach to a flaw in the order-tracking function of a plug-in associated with customer order information. According to a company blog post, the flaw allowed unauthorized access to another customer's order information under certain conditions. The company has since remediated the issue but has not disclosed technical details about the vulnerability or how attackers exploited it.

The breach was first advertised on a dark web cybercriminal forum, where a hacker claimed to possess data stolen from SafePal. The company has notified affected customers via email and set up a website for individuals to check if they were impacted.

SafePal's response emphasizes that the breach did not compromise the cryptographic security of the wallets themselves. However, the exposure of personal details—especially shipping addresses and phone numbers—creates a significant risk of social engineering and physical attacks. The company warned that affected customers are likely to face sophisticated phishing attempts, including phone calls, emails, texts, refund offers, and fake customer support messages.

Mitigations & Recommendations

Affected SafePal customers should treat any unsolicited communication referencing their order as potentially malicious. Do not click links or provide sensitive information in response to emails, texts, or calls claiming to be from SafePal or related services. Use official channels to verify any communication.

Given the physical risk associated with crypto holders, individuals with significant digital assets should review their personal security practices. This includes avoiding sharing wallet-related information publicly and being cautious about revealing crypto holdings in person. The rise in wrench attacks—where attackers use violence or threats to force victims to hand over assets—underscores the need for heightened awareness.

Organizations in the cryptocurrency sector should monitor for similar order-tracking plugin vulnerabilities and ensure that access controls are robustly implemented. Regular security audits and prompt patching of identified flaws are essential to prevent such breaches.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Tags:#safepal#hardware-wallet#data-breach#cryptocurrency#phishing

Related Articles