SafePal leaks information of nearly 40,000 hardware wallet buyers: private keys are intact, but danger is closer to the physical body.

CN
1 hour ago
The weakest link in the security chain has never been the chip or cryptography; it is people.

Written by: Little Pie

In the field of cryptographic security, there is a counterintuitive rule: knowing how much Bitcoin a person has can sometimes be more dangerous than knowing their private key.

On August 16, hardware wallet manufacturer SafePal released a security notice confirming that its order inquiry plugin had an authorization flaw, resulting in unauthorized access to the names, email addresses, phone numbers, delivery addresses, and purchase records of approximately 39,798 customers. The affected customers had placed orders between March 2, 2025, and April 11, 2026.

SafePal emphasized in the announcement that private keys, mnemonic phrases, wallet passwords, bank card numbers, and identification information were not affected. The cold storage architecture operates in a fully isolated environment, unrelated to the e-commerce servers. There is no evidence that users' wallets or funds have been directly breached.

The company also disclosed that it has discovered and taken down over 30 phishing websites related to this incident.

Why a shopping list is scarier than passwords

What attackers currently have: the real names, phone numbers, email addresses, and home addresses of nearly 40,000 people who have confirmed purchases of hardware cold wallets.

The value of this data is far greater than that of a typical e-commerce platform's order leak. Those who buy cold wallets can almost certainly be assumed to hold crypto assets, and they likely have a significant amount; users willing to spend money on specialized hardware to store assets typically do not merely hold a few hundred dollars.

Attackers do not need to hack any devices. What they can do includes:

Impersonating SafePal customer service and sending "firmware upgrade notifications" or "device recall notifications" containing real order numbers and purchase dates. Since the order information in the email is real, users are more likely to believe the entire email is genuine.

Sending physical letters or packages to users’ home addresses, accompanied by a forged QR code or "replacement device." SafePal specifically warns in the announcement to "consider any unexpected contact mentioning SafePal purchase records or hardware deliveries as suspicious," indicating that this type of attack has either already occurred or is anticipated to occur.

Cross-referencing the leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to establish a more complete user profile. Once it is confirmed that a resident at a certain address holds a large amount of crypto assets, physical intrusion (the so-called "smith attack") becomes an option.

SafePal itself also admits in its FAQ that phishing attacks may appear in various forms such as "calls, emails, text messages, letters, refund offers, firmware update requests, and counterfeit customer service communications." The length of this list itself indicates the seriousness of the issue.

Three months of silence

What is most worth questioning about this incident is the disclosure timeline.

SafePal admitted in the FAQ page that it received user reports about phishing emails as early as May but initially considered them "isolated incidents." It was not until July that a comprehensive review of the order system was conducted and not until August that the root cause was confirmed and an announcement was made.

There was approximately a three-month gap from the first report to the public disclosure. During those three months, attackers had been using the leaked data to send phishing emails, and SafePal confirmed it has discovered and taken down over 30 phishing websites. This means that users were unknowingly exposed to high-precision social engineering attacks for several months.

SafePal also disclosed a detail: its data purge routine had halted due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This means that the volume of leaked data could be greater than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.

The security paradox of cold wallets

This incident with SafePal reveals a structural contradiction in the hardware wallet industry.

The entire selling point of cold wallets is security; it protects private keys through physical isolation, preventing hackers from reaching core assets via network attacks. SafePal has indeed delivered on this promise: the leak involved the e-commerce system, not the wallet system.

However, cold wallets must be sold through e-commerce channels, which inherently requires the collection of users' real identity information: names, addresses, and phone numbers, for logistics delivery. Once this information is leaked, it precisely identifies "who is storing large amounts of crypto assets."

Ledger experienced a nearly identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. After the leak, victims reported a large number of high-precision phishing emails and SIM card hijacking attacks. Some users even received death threats. Ledger's CEO later publicly apologized, admitting there were mistakes in the company's data retention and security practices.

SafePal is now facing the same lesson being replayed, with the only difference being a smaller scale (39,800 vs. 270,000), but the attackers' script is exactly the same.

What should you do?

SafePal provided standard security advice in the announcement: do not share mnemonic phrases, do not click on unknown links, manually enter the official website address instead of clicking links in emails.

But for affected users, there are a few more practical things worth doing.

The most urgent step is to check whether you have received a "firmware upgrade" or "device recall" notification sent in the name of SafePal. If you have entered your mnemonic phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal has explicitly stated in the announcement that it will never ask for mnemonic phrases via phone, email, or any channel.

Go to SafePal's dedicated verification page to check using your order number whether you are affected; after confirming, you can request to delete your personal information. Over the next few months, consider all physical letters and packages mentioning SafePal or cold wallets as suspicious; SafePal has clearly stated it will never send physical letters.

If your delivery address is also where your crypto assets are stored, carefully assess physical security measures. This may sound like overreacting, but after the Ledger leak incident, some users indeed faced personal threats due to this data.

The crypto industry has spent ten years educating users to "safeguard your private keys." The lessons from SafePal and Ledger show that attackers have already bypassed the private keys; they target the person holding the private key. At the moment the information of "who holds crypto assets" is leaked, even the strongest cold storage cannot provide protection.

The weakest link in the security chain has never been the chip or cryptography; it is people.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink