This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$64,697+1.00%ETH$1,914+0.44%SOL$76.94+1.30%XRP$1-0.12%DOGE$0.0702-0.13%ADA$0.1751+0.59%Total Cap$2.31T+0.80%Layer Index49 Neutral
External ReportingUpdated 19 小时前

SafePal Data Breach Exposes 39,798 Crypto Wallet Owners' Details

SafePal confirmed a data breach on August 16 that exposed order records for roughly 39,798 buyers of its cryptocurrency hardware wallets.The company traced the incident to an authorization flaw in an order-tracking plug-in. Under…

SafePal Data Breach Exposes 39,798 Crypto Wallet Owners' Details
Publisher Safestate 4 分钟阅读
Image via Safestate

Layer Index

49

↑ 5 pts in 24h

SafePal confirmed a data breach on August 16 that exposed order records for roughly 39,798 buyers of its cryptocurrency hardware wallets.The company traced the incident to an authorization flaw in an order-tracking plug-in. Under certain conditions, that flaw let one request retrieve another customer's order details.

The data breach that SafePal disclosed covers orders placed between March 2, 2025 and April 11, 2026. Exposed fields include names, email addresses, shipping addresses, phone numbers, and purchase details. A threat actor has since advertised the stolen records on a cybercrime forum, though no one has independently verified that the seller holds the data.

What the Breach Did and Did Not Expose

The stolen information sits entirely on the e-commerce side of the business. Order histories and delivery details lived in the order-processing environment. None of it touches the wallet software or the devices themselves.

SafePal stated that the data breach did not expose seed phrases, private keys, wallet passwords, bank details, payment card numbers, or identification documents. The company does not collect those categories at all. Investigators found no evidence that the intrusion reached customer wallets or funds.

That distinction matters, but it does not make the exposure harmless. The data breach handed attackers a precise picture of who buys SafePal hardware, where those people live, and which model they own. For a criminal building a target list, that combination beats a generic marketing database.

How SafePal Uncovered the Data Breach

SafePal received its first warning about the data breach in early May 2026, when a customer reported behaviour consistent with the flaw. Staff treated it as an isolated case. They escalated it into a formal investigation and added protections. The order-processing stack spans internal components, external integrations, and logistics partners, so several explanations stayed plausible.

In July, the team began a full review and rebuild of the order-processing system. That work surfaced the authorization flaw in the plug-in's order-tracking function. Engineers patched it and layered on further controls, and an independent security firm is now validating the fix and auditing the wider system.

SafePal also found that the data breach reached further back than it should have. A configuration error had quietly broken a scheduled data-cleanup process between September 2025 and April 2026. Records that should have aged out stayed live, stretching exposure as far back as March 2025.

A Threat Actor Claims to Be Selling the Records

A seller on a cybercrime forum now claims to hold the stolen order data. The listing cites the same order window and roughly the same customer count that SafePal published about the data breach. That overlap lends the claim some weight without confirming it.

The seller also offers prospective buyers order IDs and shipping countries pulled from the trove. Those samples can go through the company's own exposure-checking page, which turns a customer safety tool into a proof-of-authenticity service for the sale. If the claims hold up, buyers can validate the goods before paying.

No one outside the forum has confirmed that the seller possesses the full dataset. Criminal marketplaces carry a steady volume of recycled and fabricated listings. Until someone independently examines a sample, the sale sits as an allegation.

Why Order Data Puts Wallet Owners at Risk

Phishing built on this material does not need to guess. An attacker can cite a real order number, the correct device model, and a genuine delivery address. Those details strip away most of the cues people rely on to spot a fake. Customers began reporting emails and calls impersonating SafePal in May, months before the data breach became public.

One reported message claimed the X1 hardware wallet carried a newly discovered vulnerability and demanded an urgent firmware update. The link to this incident remains unconfirmed, though the pretext fits the pattern closely. Any approach that ends with a user typing a seed phrase into a webpage achieves what the intrusion could not.

The physical dimension deserves attention too. Confirmed home addresses tied to confirmed crypto ownership support mail-based scams and counterfeit replacement devices arriving unannounced. In rare cases, they support direct coercion. The company has already taken down more than 30 fraudulent websites and phishing links.

What Affected Customers Should Do

SafePal published a verification page where customers can check their orders against the data breach, using an order number and a shipping country. The company also emailed every affected person on August 16. Anyone unsure about a message should verify it through that page rather than replying.

An affected order does not force a hardware replacement or a transfer of funds. The devices remain secure and the keys never left them. Anyone who entered a seed phrase after a suspicious call or website should treat that wallet as compromised. Move the assets to a new wallet on a trusted device.

Legitimate support staff never ask for recovery phrases. Typing the official web address manually beats following any link. An unexpected hardware delivery referencing a past purchase warrants suspicion.

Final Thoughts

Two failures compounded here. One authorization flaw in a plug-in opened the door. A broken retention job then kept fourteen months of order records sitting behind it. The company has closed both gaps, cut its retention window to 90 days, and purged affected personal data from active servers.

For customers, the exposure does not fade with the patch. Order details do not expire, and the people buying them can afford to be patient. SafePal has fixed the flaw, but the data breach will keep feeding phishing attempts for months. The only durable defence is a flat refusal to share wallet credentials with anyone who asks.

突发新闻

Never miss a breaking story

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by Safestate

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

相关报道