AI · The Block
Wallet provider SafePal confirms data breach exposed personal info of nearly 40,000 customers
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
✓ KHAO Verified
Crypto wallet provider SafePal said in an X post on Sunday that an authorization flaw in its order-tracking system allowed unauthorized access to the personal data belonging to approximately 39,798 customers.
Key facts
- On Thursday, that a breach at wallet provider Trezor's shipping partner ShipMonk exposed information belonging to nearly 14,000 customers
- SafePal also said it has identified and taken down more than 30 fraudulent websites and phishing links tied to the scam
- Crypto wallet provider SafePal said in an X post on Sunday that an authorization flaw in its order-tracking system allowed unauthorized access to the personal data belonging to approximately 39,798
- A Reddit post from July 3 also reported being contacted by someone who knew the user's "name, address, phone, email, and my order details from my purchase last year" and directed to the safepal
Summary
The exposed information includes customer names, email addresses, shipping addresses, phone numbers, and purchase details, according to SafePal's incident report. "This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal wrote. The company warned that attackers might target affected users with phishing and impersonation attempts, posing as SafePal employees to offer firmware updates, refunds, or replacement devices before attempting to glean wallet credentials from those users. SafePal has not disclosed when the flaw was introduced, when customer records were first accessed, or how many attackers may have obtained the data.