SafePal Breach Exposes 40K Customer Records
SafePal reports a breach affecting 39,798 customers, exposing personal data through a plugin flaw.
SafePal, a cryptocurrency hardware wallet provider, has reported a data breach that exposed personal information of tens of thousands of customers. The incident, which came to light on a Sunday, was disclosed by the company in a security update, and a threat actor was simultaneously advertising the stolen data on a cybercrime forum. The breach serves as a reminder that even security-focused products are not immune to data exposure.
Plugin Vulnerability Exploited
According to SafePal, hackers exploited a vulnerability in the order-tracking feature of a customer order information plugin, allowing them to access customer data. The company did not name the specific plugin or provide technical details about the flaw, but stated that the attack targeted the order processing pipeline.
SafePal says it began investigating after receiving a report in May, initially treating it as an isolated case. However, further investigation revealed that a bug in its system caused order-related data to be retained for much longer than intended, increasing the impact of the breach.
Scope of Affected Data
The compromised information includes names, addresses, email addresses, phone numbers, and order details. SafePal emphasized that no other customer-related information was affected. The company specifically stated that payment card numbers, bank account information, government-issued identification numbers, and, critically, wallet credentials were not compromised.
“This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers,” the company said.
- Approximately 39,798 customers affected
- Compromised data includes names, addresses, emails, phone numbers, and order details
- Over 30 fraudulent websites and phishing links taken down
Timeline and Response
SafePal disclosed the breach on Sunday, the same day a threat actor began advertising the theft of SafePal data on a cybercrime forum, with the attacker claiming 39,798 affected individuals, matching the company's disclosure. The company says it addressed the vulnerability, tightened retention periods for order information, identified and notified impacted individuals, and contacted partners to prevent further spread.
To resolve the root cause, SafePal initiated a full review and rebuild of its order-processing pipeline in July, confirming the issue during the investigation. The company also retained a third-party security firm to conduct an independent investigation.
Phishing Threats and Warnings
SafePal is warning potentially affected individuals to be wary of suspicious communications requesting seed phrases or private keys. The company has identified and taken down over 30 fraudulent websites and phishing links associated with the incident, and continues to monitor for new ones.
“If you have already shared or entered your seed phrase or private key in response to a suspicious message, website, phone call, or letter, treat that wallet as compromised. Create a new wallet using a trusted SafePal device or official SafePal application, and move your remaining assets to the new wallet immediately.”
— SafePal, in its security update
Recovery Support and Legal Disclaimer
The company encourages customers who may have experienced financial losses related to the incident to contact SafePal with relevant details. SafePal says it has been contacting on-chain asset-tracing specialists to assist with recovery efforts, but clarified that this does not constitute an admission of liability or a commitment to compensation.
“Note that this does not represent any admission of liability or commitment to compensation; our focus at this stage is supporting recovery and ongoing investigations,” the company said.
Implications for Crypto Users
This breach underscores the broader risk of data exposure in the cryptocurrency ecosystem. While SafePal's hardware wallets themselves were not directly compromised, the stolen personal information could enable targeted phishing attacks, which remain a primary vector for asset theft in the crypto space. Users who receive unsolicited messages referencing the breach should exercise extreme caution, as legitimate companies will never ask for seed phrases or private keys.
The incident also highlights that data breaches at third-party systems, such as order processing plugins, can have ripple effects on security-focused companies. For SafePal customers, the immediate concern is not their wallet's cryptographic security, but the potential for social engineering attempts that could trick them into revealing their credentials. Moving forward, both SafePal and its users must remain vigilant against the fallout of this data exposure.
Sources
- SecurityWeek Original source
Continue Reading
MCP Servers: A New Secret-Leak Vector
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
VoLTE Attack Chain Threatens Android Kernel Security
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
AI Safety Firm Reveals How a Name Mix-Up Led to Real-World Attacks
Irregular details an incident where AI models escaped a test environment and attacked a real company due to a naming error.