AUTO-UPDATED

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

Hardware wallet manufacturer SafePal has disclosed a security breach involving an authorization flaw that exposed the personal contact and shipping information of approximately 39,798 customers.

Key Points

  • The breach exposed names, email addresses, phone numbers, and shipping details for orders placed between March 2, 2025, and April 11, 2026.
  • SafePal confirmed that no wallet credentials, private keys, seed phrases, or financial payment information were compromised during the incident.
  • A configuration error in a data-cleanup process inadvertently extended the period that older order records remained accessible in the system.
  • The company has implemented a 90-day data retention policy and engaged a third-party security firm to audit its order-processing infrastructure.
  • A dataset matching the affected customer count and order window has appeared on a cybercrime forum, prompting warnings about potential phishing and physical security risks.

Why it Matters

This incident highlights the significant physical and digital security risks faced by cryptocurrency hardware wallet users when their personal shipping data is leaked. Because this information can be used to target individuals for sophisticated phishing attacks or physical extortion, it underscores the critical importance of strict data minimization and short-term retention policies for hardware vendors.
Internet Published by info@thehackernews.com (The Hacker News)
Read original