SafePal has confirmed a security incident affecting approximately 39,798 customers after a vulnerability in its order-tracking system allowed unauthorized access to purchase information. According to SafePal's disclosure, the incident involved orders placed between March 2, 2025 and April 11, 2026.
The exposed information included names, email addresses, phone numbers, shipping addresses, and order details. While this may appear less severe than a direct wallet compromise, the information is particularly sensitive in crypto because it can establish a link between a specific individual and ownership or use of a hardware wallet.
The most important distinction is that SafePal says the incident did not affect seed phrases, private keys, wallet passwords, or crypto assets. Bank account information, payment card numbers, and government-issued identification were also not part of the exposed data. SafePal says the vulnerability has been fixed and additional security measures have been implemented.
However, the absence of private-key exposure does not eliminate the security risk. The more immediate concern is phishing and impersonation. Once attackers know someone's name, address, phone number, and purchase history, they can create highly convincing messages that appear to come from SafePal, potentially referencing an actual order, device update, or security verification.
SafePal has emphasized that seed phrases, private keys, and passwords should never be shared with anyone. The company says affected customers were notified individually and that a mechanism is available for checking whether an account was impacted.
The incident is a useful reminder that crypto security does not stop at protecting a private key. Personal information surrounding the ownership of a wallet can also become a valuable target.
Is targeted phishing becoming almost as serious a threat as direct private-key compromise in crypto security incidents? 🤔
(DYOR). $ACE $EDEN #Colecolen #anhbacong #anh_ba_cong $SAFE
The exposed information included names, email addresses, phone numbers, shipping addresses, and order details. While this may appear less severe than a direct wallet compromise, the information is particularly sensitive in crypto because it can establish a link between a specific individual and ownership or use of a hardware wallet.
The most important distinction is that SafePal says the incident did not affect seed phrases, private keys, wallet passwords, or crypto assets. Bank account information, payment card numbers, and government-issued identification were also not part of the exposed data. SafePal says the vulnerability has been fixed and additional security measures have been implemented.
However, the absence of private-key exposure does not eliminate the security risk. The more immediate concern is phishing and impersonation. Once attackers know someone's name, address, phone number, and purchase history, they can create highly convincing messages that appear to come from SafePal, potentially referencing an actual order, device update, or security verification.
SafePal has emphasized that seed phrases, private keys, and passwords should never be shared with anyone. The company says affected customers were notified individually and that a mechanism is available for checking whether an account was impacted.
The incident is a useful reminder that crypto security does not stop at protecting a private key. Personal information surrounding the ownership of a wallet can also become a valuable target.
Is targeted phishing becoming almost as serious a threat as direct private-key compromise in crypto security incidents? 🤔
(DYOR). $ACE $EDEN #Colecolen #anhbacong #anh_ba_cong $SAFE