On August 16, SafePal, a hardware wallet company that Binance has invested in, issued a statement on X, admitting that a security incident occurred, and that information from nearly 40,000 users was stolen.

Although SafePal said that the core information—like recovery phrases, private keys, and wallet passwords—was fine, they scraped all the delivery information users provided when purchasing the hardware wallet, including their names, email addresses, shipping addresses, and phone numbers.

The reason for the leak was a third-party plugin on the SafePal website that lets users check the status of their orders. It had an "authorization vulnerability." Originally, users could enter an order number only to view their own purchase records. But someone discovered it: by simply changing a parameter, they could view other people’s delivery addresses and phone numbers.

SafePal said it only “recently found the root cause,” but in reality, as early as July, users were already reporting online that they had received scam calls from people who knew their name and address.

That is to say, SafePal users’ data may have been exposed on the internet, bare for more than a month.

This year has seen frequent security incidents in the crypto industry. Besides the DeFi thefts everyone has long grown accustomed to, even so-called “the safest” hardware wallets keep running into problems.

This year in January, Ledger, the leading global hardware wallet provider, had trouble paying its partner Global-e. As a result, a batch of customers’ names and contact information were leaked.

Although this incident, like SafePal, does not involve core wallet credentials such as seed phrases or private keys, historically Ledger users’ privacy breaches have led to “wrench attacks,” and even Ledger’s co-founder became a victim in 2025.

On July 30 this year, Canadian hardware wallet company Coldcard—claimed to be “absolutely trustworthy at the cryptography level”—was stolen.

The attacker exploited a firmware vulnerability that existed as early as March 2021 and had been lying dormant for 5 years. They found that some Coldcard devices did not generate mnemonic phrases with sufficient randomness; the key strength dropped from 128 bits to as low as 40 bits, enabling hackers to brute-force the keys.

Starting July 30, the hackers carried out the theft in four waves. Within 41 minutes, they siphoned roughly $70 million from 1,196 addresses. Ultimately, the losses rolled past $130 million, affecting more than 5,200 addresses, making it the third-largest cryptocurrency theft case as of 2026 to date.

The SafePal whose users’ information was leaked this time was invested in by Binance and is a hardware wallet project that has been launched on Binance Launchpad—making it part of Binance’s new wave.

It claims it can directly move Binance’s trading liquidity and fiat in/out channels into the wallet app, and it also keeps the entry price under $50, winning over many crypto investors.

Although SafePal delivers extreme security at the “offline signing” layer, it uses industry-average protection at the “e-commerce orders” layer.

Now hackers understand this even better. They don’t bother to chew through the hard nut of firmware encryption; instead they target weaker links like the order system. Once they have information such as names, addresses, and phone numbers, they can use it for the next steps: targeted phishing, impersonating customer support, or even in-person “wrench attacks” (forcing you to hand over your private key with violence).

Even if criminals didn’t target them, it’s still a bad thing if this information is in the hands of “Uncle Hat” (law enforcement) or the tax authorities.