The crypto wallet company SafePal said on Sunday that it had “recently” found and fixed a vulnerability in a system containing users’ order information, and that, if exploited, this would have allowed potential attackers to access said information. But it added that apparently someone did access it without authorization, exposing the data of customers who placed orders from March 2 of last year to April 11 of this year.
SafePal customers probably understand this intuitively, but outsiders might not: this doesn’t mean anyone’s crypto was stolen or directly jeopardized. Like Ledger, which notified users of a third-party data breach earlier this year, SafePal makes hardware wallets, which are usually thin little gadgets that look like a mix between a credit card and a tiny smartphone. What was exposed was the identifying information of 39,798 people who likely bought SafePal devices.
SafePal says the exposed data includes, “name, email address, shipping address, phone number, and purchase details.”



.webp)

