The company stressed that the core security of its wallets remains intact. No cryptocurrency funds, seed phrases, private keys, bank passwords, payment card numbers or government-issued IDs were compromised. Still, SafePal warned that exposed users face heightened phishing and impersonation risks.
Customers had posted online about being targeted by phishing attempts as early as July, though SafePal said it found the root cause of the breach only recently.
Patched flaw, 30-plus fake sites removed
SafePal said it patched the vulnerability and introduced additional security measures. The company notified all affected customers by email from [email protected] on Sunday and hired an independent third-party security firm to audit the fix and review its order-processing systems.
SafePal also identified and removed more than 30 fraudulent websites and phishing links associated with the breach. Going forward, the company said it will retain customers’ personal data in its order-processing system for only 90 days from the date of collection.
Anyone who shared private keys or seed phrases in response to a phishing email, phone call or letter should treat their wallet as compromised and transfer assets to a new wallet, SafePal said. Customers can use a verification tool on SafePal’s website to check whether their data was affected.
Hardware wallets are not bulletproof
The SafePal incident follows a recent hack of Coldcard hardware wallets in which an attacker reportedly stole at least $120 million in bitcoin, CoinDesk reported. The two breaches are different in nature, but together they underline a simple point: no crypto storage solution is entirely risk-free. Security experts have long urged holders to assess concentration risk and, where appropriate, diversify both their holdings and the wallets used to store them.
For Northeast Philadelphia residents who bought a SafePal device during the affected window, the immediate step is straightforward: check SafePal’s verification tool, watch for suspicious emails or letters referencing your order, and never share seed phrases or private keys with anyone who contacts you, no matter how official the message looks.