Digital Wallet
By Jean-Luc Maracon
1 / 15
What the Plugin Actually Leaked. The breach came through a third-party plugin SafePal used to track customer orders.
2 / 15
The Disclosure Delay Problem. Here's where it gets messy. Another researcher, Specter, pointed out that phishing reports tied to…
3 / 15
Trezor's Shipmonk Breach and a Wider Pattern. SafePal isn't alone in this. Trezor went through something similar when its shipping provider,…
4 / 15
A plugin broke. Nearly 40,000 people paid for it.
5 / 15
SafePal, the Seychelles-based hardware wallet maker, confirmed a data breach affecting 39,798 customers after a faulty order-tracking plugin leaked sensitive personal information…
6 / 15
The company says it's fixed the plugin flaw now.
7 / 15
The breach came through a third-party plugin SafePal used to track customer orders. Unauthorized individuals got into that system and pulled personal data.
8 / 15
SafePal warned customers directly about the phishing risk. Fraudulent emails, fake websites, deceptive messages designed to pull wallet credentials out of people who already…
9 / 15
Security researcher Tay flagged that the exposure goes beyond phishing. Physical data like shipping addresses opens the door to targeted, real-world attacks on people known to…
10 / 15
Here's where it gets messy. Another researcher, Specter, pointed out that phishing reports tied to this breach started coming in as early as April.
11 / 15
That gap is a real problem. Affected users had no way to know they were being targeted using their own leaked information. Some of them probably clicked things they shouldn't have.
12 / 15
See also: SafePal Data Breach Hits 40,000 Crypto Wallet Users After Phishing Wave
13 / 15
One affected customer went public with a specific complaint: his data had already been deleted before the breach disclosure came out. That's not a minor detail.
14 / 15
SafePal says it has since reduced data retention to 90 days and taken down 30 websites connected to scams targeting its users. Thirty sites.
15 / 15
SafePal isn't alone in this. Trezor went through something similar when its shipping provider, Shipmonk, suffered a breach that compromised customer data across multiple countries.
The Currency Analytics
Want the full story?