Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info

Cryptocurrency security firm SafePal suffered a data breach exposing the personal order information of nearly 40,000 customers due to an authorization flaw in a plug-in. While sensitive financial assets like private keys and seed phrases remain secure, the company has patched the vulnerability and is notifying affected users. The incident highlights the ongoing risks associated with hardware wallet providers and the importance of diversifying storage solutions.
Why it matters
This breach underscores that even hardware-based security companies are vulnerable to data leaks, which can serve as a vector for phishing attacks against their user base.
The exposed data included names, physical addresses, and contact details, putting affected users at risk of phishing and impersonation attempts. However, the breach did not compromise any cryptocurrency funds, passwords, or private wallet keys.
SafePal is a cryptocurrency security company that provides physical hardware wallets and software applications designed to help investors safely store and manage their digital assets.
The latest exploit follows a recent hack of Coldcard hardware wallets , in which the attacker reportedly stole at least $120 million in bitcoin. While the incidents do not necessarily point to a systemic weakness in hardware wallets, they show that no crypto-storage solution is entirely risk-free. They also validate calls to assess concentration risk and, where appropriate, to diversify both crypto holdings and the wallets used to store them.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in