SafePal Breach Exposes 40,000 Crypto Wallet Customers' Personal Data
SafePal, a maker of cryptocurrency hardware wallets, has confirmed a data breach affecting roughly 39,798 customers after a flaw was discovered in a third-party order tracking plugin. The exposed data includes names, email addresses, shipping addresses and phone numbers.
Importantly, SafePal confirmed that no private keys or seed phrases were compromised, meaning customers' cryptocurrency holdings remain secure from direct theft through this breach. However, the leaked contact and address details raise concerns about follow-on attacks, particularly phishing attempts and, given the crypto industry's history, targeted physical attacks against individuals known to hold digital assets.
This incident highlights a growing risk for any business handling customer shipping and contact data: third-party plugins and integrations can become weak points even when core systems remain secure. Businesses that ship physical products, especially those linked to high-value goods, should review the security posture of every plugin and vendor connected to their customer data.