ZeroHour
Product

SafePal hardware wallets

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

SafePal Says 39,798 Customers Hit by Data Breach

Crypto wallet maker SafePal disclosed a breach exposing order data of 39,798 customers via a plugin authorization flaw; keys and seed phrases unaffected.

SafePal, a Singapore-based cryptocurrency security company, said an authorization flaw in an order-tracking plugin let attackers access order records placed between March 2, 2025 and April 11, 2026. Exposed data includes names, emails, addresses, phone numbers, and purchase details for about 39,798 customers, while seed phrases, private keys, wallet passwords, and payment data were not exposed. A threat actor advertised the same dataset on a cybercrime forum, and affected customers were notified by email on August 16. The company patched the flaw, reduced data retention to 90 days, and removed over 30 fraudulent phishing websites.

Security Affairs · 29d agoData breach in the wild

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

SafePal confirmed nearly 40,000 customers' order data was stolen, the third hardware wallet maker breached in a month after Trezor and Coinkite.

SafePal confirmed a breach exposing names, emails, shipping addresses, phone numbers, and purchase details of customers who ordered between March 2, 2025 and April 11, 2026, caused by a flaw in an order-tracking plugin. The company stressed wallets, seed phrases, and private keys remain secure, and all impacted customers were notified by email. A hacker advertised the stolen data on a dark web forum, and SafePal warned of targeted phishing via fake support calls and refund offers. CertiK data cited in the report shows 52 wrench attacks worldwide in H1 2026 with $124 million in losses, up 33% year-over-year.

The Record · 29d agoData breach in the wild

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.