Digital Wallet

Story: SafePal’s 39,798-Customer Data Leak Exposes Shipping Addresses and Phone Numbers

By Jean-Luc Maracon

1 / 15

What the Plugin Actually Leaked. The breach came through a third-party plugin SafePal used to track customer orders.

2 / 15

The Disclosure Delay Problem. Here's where it gets messy. Another researcher, Specter, pointed out that phishing reports tied to…

3 / 15

Trezor's Shipmonk Breach and a Wider Pattern. SafePal isn't alone in this. Trezor went through something similar when its shipping provider,…

4 / 15

A plugin broke. Nearly 40,000 people paid for it.

5 / 15

SafePal, the Seychelles-based hardware wallet maker, confirmed a data breach affecting 39,798 customers after a faulty order-tracking plugin leaked sensitive personal information…

6 / 15

The company says it's fixed the plugin flaw now.

7 / 15

The breach came through a third-party plugin SafePal used to track customer orders. Unauthorized individuals got into that system and pulled personal data.

8 / 15

SafePal warned customers directly about the phishing risk. Fraudulent emails, fake websites, deceptive messages designed to pull wallet credentials out of people who already…

9 / 15

Security researcher Tay flagged that the exposure goes beyond phishing. Physical data like shipping addresses opens the door to targeted, real-world attacks on people known to…

10 / 15

Here's where it gets messy. Another researcher, Specter, pointed out that phishing reports tied to this breach started coming in as early as April.

11 / 15

That gap is a real problem. Affected users had no way to know they were being targeted using their own leaked information. Some of them probably clicked things they shouldn't have.

12 / 15

See also: SafePal Data Breach Hits 40,000 Crypto Wallet Users After Phishing Wave

13 / 15

One affected customer went public with a specific complaint: his data had already been deleted before the breach disclosure came out. That's not a minor detail.

14 / 15

SafePal says it has since reduced data retention to 90 days and taken down 30 websites connected to scams targeting its users. Thirty sites.

15 / 15

SafePal isn't alone in this. Trezor went through something similar when its shipping provider, Shipmonk, suffered a breach that compromised customer data across multiple countries.

The Currency Analytics

Want the full story?