Cookdata (OP)
Legendary

Activity: 1764
Merit: 1462
Not Your Keys, Not Your Bitcoin
|
 |
August 16, 2026, 12:11:20 PM |
|
Safepal wallet team announced that 39,798 customers that placed orders between March 2 2025 to 11 April 2026 have their order details exposed. Dear community,
While your SafePal wallet, seed phrase, and private keys are secure; we identified a flaw in the order-tracking plug-in that led to unauthorized access to information of a subset of customers.
The issue has been fixed with additional security measures introduced.
The incident impacts approximately 39,798 customers who placed orders between March 2, 2025 and April 11, 2026. Exposed information includes name, email address, shipping address, phone number, and purchase details. https://www.safepal.com/en/blog/security-update
|
|
|
|
Zaguru12
Legendary

Activity: 1512
Merit: 1265
Instant Crypto Withdrawals
|
 |
August 16, 2026, 12:23:40 PM |
|
2 hardware data breach in space of 3 days, How do you keep users data of over three months stored in your custody.
How are we sure that this breaches are even happening now? Or have they happened long before and most of the hardware wallets actually hide it and are using this period of time to announce their breaches probably thinking what could be worse than the coldcard breach?
Seriously I am not convince with the kind of apology usually offered after this incidents.
Now what do we have against ledger hardware wallets again except their recovery policy and been closed source because if it is data breaches even open sources are now getting easily exploited.
At this point everyone should simply set up their own cold storage
|
|
|
|
|
Yamane_Keto
|
 |
August 16, 2026, 12:44:32 PM |
|
2 hardware data breach in space of 3 days,
I don't think this happened in the past few days, I found a Reddit member complaining that their data had been leaked and was being exploited. https://www.reddit.com/r/CryptoCurrency/comments/1t715wg/safepal_hardware_wallet_had_a_breach_and_says_its/SafePal (hardware wallet) had a breach and says it's not their responsibility To make a long story short, I bought two SafePal S1 Wallets last year. Yesterday I got a call from a person claiming to be from SafePal. At first, I denied having purchased any SafePal products before, assuming it's a scam. Then, they told me my full name and home address and my exact order details. They knew how many and which products I bought and the exact payment method I used.
Upon checking my email, I saw that they had sent an email outlining details to update my firmware as well. That email, too, included my exact order information and home address.
When I asked SafePal about whether or not they had been made aware of any breach, they simply said that they're not responsible for such issues because "as a decentralized wallet", they don't store any data and that it "may have been because of a partner having been compromised). I was like, is this a joke? How can they not store data when they take physical orders and payments through their own entity, SafePal LTD??
It is completely unacceptable and unprofessional for a hardware wallet company to not take any kind of responsibility for their customers' entire data being exposed.
They didn't even inform any users even after I made it clear to them multiple times that potentially thousands of customers' data had been compromised. This is complete and utter negligence.
Never buy SafePal products. They have been denying these allegations for the past 3 months.
|
|
|
|
PX-Z
Legendary
Online
Activity: 2268
Merit: 1367
Wallet Transaction Notifier - @txnNotifierBot
|
 |
August 16, 2026, 03:40:46 PM |
|
And here we are again! I don't think this happened in the past few days, I found a Reddit member complaining that their data had been leaked and was being exploited. ...
Based on safepal announcement the affected users of their purchase was march to april, and the reddit post was 3 months ago. Then the hack probably happened between april-may (days to weeks before the reddit post). And yet, safepal only announce this week. That's how BS they are and they just said "we are extremely sorry" like its just another data info hack.
|
|
|
|
OmegaStarScream
Staff
Legendary

Activity: 4298
Merit: 7571
|
 |
August 16, 2026, 03:56:35 PM |
|
What's happening in the crypto scene feels unreal at this point. Not a single day seem to pass anymore without either a data leak, or a platforms losing a few millions of dollars (due to an exploit) is announced. Makes you think how bad things are going to get when AI companies continue to release more advanced models.
|
|
|
|
Charles-Tim
Legendary

Activity: 2366
Merit: 6496
Leading Crypto Sports Betting & Casino Platform
|
 |
August 16, 2026, 04:02:59 PM |
|
At this point everyone should simply set up their own cold storage
I do not know the reason people are not discussing the reality when discussing about hardware wallets, but if it a centralized exchange, KYC is frowned on. I think the danger in hardware wallet data breach is more than data breach on exchanges, although none is good among them. Although, people buying hardware wallet may not know that their information is like KYC despite that it may not be regarded as KYC to some people.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
Alvin_talk
Full Member
 

Activity: 269
Merit: 133
I don't want peace, I love problem always
|
 |
August 16, 2026, 05:21:24 PM |
|
I call this a medicine after death situation, the information was released so late and customers have already fallen for these phishing emails. How will a firm curb such information from customers for such a long time. It is obvious they don't really care about their customers, their major aim is just to milk them.
Considering the initial denial, I am compelled to believe Safepal sold these personal data to the so called attackers. It looks more like an orchestrated plan which the company is fully aware of or even part of it, thus, they denied the occurrence of this data breaches when customers raised concern earlier.
|
|
|
|
|
|
Meuserna
|
 |
August 16, 2026, 05:28:44 PM |
|
At this point everyone should simply set up their own cold storage
That was the decision I made when Ledger's key extraction firmware was outed. But I should have made that decision when Ledger leaked their entire customer database. I switched to Krux and SeedSigner, which are both free and open source firmware that runs on off the shelf parts, so there's no customer database to be in.
|
|
|
|
goldkingcoiner
Legendary

Activity: 2870
Merit: 3065
HoDL
|
 |
August 16, 2026, 05:33:42 PM |
|
What's happening in the crypto scene feels unreal at this point. Not a single day seem to pass anymore without either a data leak, or a platforms losing a few millions of dollars (due to an exploit) is announced. Makes you think how bad things are going to get when AI companies continue to release more advanced models.
It almost feels like the whole thing was orchestrated or something to get people to panic and start selling their coins... AI is both a sword and a shield. On one hand, it can easier find ways to hack wallets but on the other hand AI can be used to create wallets with far tougher security. So hard to say, really. Personally, I have never even heard of "SafePal Wallet". There are way too many wallets and every vibe coder thinks what the world needs is another crappily coded wallet.... Let's see how current wallets handle a stronger threat...
|
|
|
|
|
X-ray
|
 |
Today at 03:23:47 AM |
|
Is it that common hardware wallet manufacturer to be dismissive and slow? I've started to see this pattern, users reported some problem and the company simply shrug it off because they thought it's nothing. If a user said they are getting scam calls impersonating the company right after buying the hardware wallet, it'd be enough to start a data breach investigation but only after few months they are announcing the breach. Is there a chance that they knew there is something wrong but wait until other better and bigger hardware wallet suffer the same problem and promptly announce their breaches as well to reduce backlash??
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
m2017
Legendary

Activity: 2576
Merit: 1705
keep walking, Johnnie
|
 |
Today at 04:07:08 AM |
|
Safepal wallet team announced that 39,798 customers that placed orders between March 2 2025 to 11 April 2026 have their order details exposed.
March 2, 2025, to April 11, 2026 - that’s 17 months, or nearly a year and a half. That is how long Safepal kept customer order information on file. Look, similar leaks have happened before, and some HW manufacturers managed to adapt by cutting their data retention period to 3 months (though even that isn't a complete fix). Why didn't this company do the same? They seem incapable of learning from other's mistakes. Can see the result for yourself: 39,798 customers. That number could have been lower. Cryptoindustry-wide problem is being exposed yet again. Why haven't HW manufacturers found a solution to eliminate this issue? Negligence? What’s at stake are cryptoassets - and potentially the health and lives of their customers. Do "sellers" care only about sales and profits, while user interests mean nothing? It’s the same "teething troubles" over and over again. Couldn't they have encrypted the data? It’s disappointing. By the way, this implies that nearly 40,000 devices were sold over those 17 months (assuming the figure covers all sales, not just specific regions). That works out to around 2,300 units a month, doesn't it? Is that the scale of the company's sales?
|
|
|
|
SFR10
Legendary

Activity: 3808
Merit: 4153
|
 |
Today at 08:54:44 AM |
|
It looks more like an orchestrated plan which the company is fully aware of or even part of it, thus, they denied the occurrence of this data breaches when customers raised concern earlier.
Based on the FAQ section of their " Scam Protection" page, when the first report came, they thought it was just an isolated case, but they did start a formal investigation at that time [there's no doubt that they should've done a better job in protecting & informing their customers about the data breach in question, but it appears that it took some time also to make sure the issue didn't extend to other third-parties that are involved]. I switched to Krux and SeedSigner, which are both free and open source firmware that runs on off the shelf parts, so there's no customer database to be in.
Great move... Using cash to purchase from official resellers with brick-and-mortar stores can also protect users from such data breaches.
|
|
|
|
rdluffy
Legendary

Activity: 3052
Merit: 2057
|
 |
Today at 01:06:58 PM |
|
I won a Safepal from Jumper Exchange I had to pay for shipping and taxes, it was in December 2025. I even posted about it here: https://bitcointalk.org/index.php?topic=5257785.msg66238255#msg66238255I think I’m in that database, unfortunately  I don’t even mind getting phishing emails because I hardly ever open them and I’m always careful The really bad and dangerous part is that my physical address and full name have been exposed 
|
|
|
|
|
|
| | ..1win.. | █████████████████████████ █████████████████████████ ████████████▀░░░▀▀▀▀█████ █████████▀▀▀█▄░░░░░░░████ ████▀▀░░░░░░░█▄░▄░░░▐████ ████▌░░░░▄░░░▐████░░▐████ █████░░░▄██▄░░██▀░░░█████ █████▌░░▀██▀░░▐▌░░░▐█████ ██████░░░░▀░░░░█░░░▐█████ ██████▌░░░░░░░░▐█▄▄██████ ███████▄░░▄▄▄████████████ █████████████████████████ █████████████████████████ | ..POKER.. | █████████████████████████ █████████████████████████ ███████████▀▀▀███████████ ███████▀▀░░▄▄▄░░▀▀███████ ██████▄░░░░███░░░░▄██████ █████░▀▀█▄▄░░░▄▄█▀▀░█████ █████░██░░▀▀█▀▀░░██░█████ █████░░░░░░░█░██░▄▄░█████ █████▄░░░▄▄░█░▄▄░▀▀▄█████ ███████▄▄▀▀░█░▀▀▄▄███████ ███████████▄█▄███████████ █████████████████████████ █████████████████████████ | ..GAMES.. | █████████████████████████ █████████████████████████ ████████▀▀░░░░░▀▀████████ ██████░░▄██▄░▄██▄░░██████ █████░░████▀░▀████░░█████ ████░░░░▀▀░░░░░▀▀░░░░████ ████░░▄██░░░░░░░██▄░░████ ████░░████░░░░░████░░████ █████░░▀▀░▄███▄░▀▀░░█████ ██████░░░░▀███▀░░░░██████ ████████▄▄░░░░░▄▄████████ █████████████████████████ █████████████████████████ | | |
|
|
|
|
Yamane_Keto
|
 |
Today at 03:36:14 PM |
|
Is it that common hardware wallet manufacturer to be dismissive and slow?
I've started to see this pattern, users reported some problem and the company simply shrug it off because they thought it's nothing.
Customer personal data is supposed to be retained for 90 days and then deleted; however, I read the privacy policy, updated yesterday, and there is no clause specifying the data retention. The recent hack proved that they had retained the data for over a year. What's happening in the crypto scene feels unreal at this point. Not a single day seem to pass anymore without either a data leak, or a platforms losing a few millions of dollars (due to an exploit) is announced. Makes you think how bad things are going to get when AI companies continue to release more advanced models.
Customer data is shared with many third parties, and inevitably one of them will be negligent in securing it.
|
|
|
|
The Sceptical Chymist
Legendary
Online
Activity: 4158
Merit: 7368
♻️ Automatic Exchange
|
 |
Today at 05:46:23 PM |
|
Based on safepal announcement the affected users of their purchase was march to april, and the reddit post was 3 months ago. Then the hack probably happened between april-may (days to weeks before the reddit post). And yet, safepal only announce this week. That's how BS they are and they just said "we are extremely sorry" like its just another data info hack.
Yep, but that's basically how every company that experiences a data breach responds, although some are a bit more helpful depending on their size and how much they value their reputation. And why does none of this surprise me? Also, why aren't crypto companies using AI to look for holes in their code faster than hackers? That may not be relevant to the Safepal situation, but in general it doesn't seem to be happening--only customers finding out that they got screwed. Tsk, tsk.
|
░░░░▄▄████████████▄ ░▄████████████████▀ ▄████████████████▀▄█▄ ▄███████▀▀░░▄███▀▄████▄ ▄██████▀░░░▄███▀░▀██████▄ ██████▀░░▄████▄░░░▀██████ ██████░░▀▀▀▀░▄▄▄▄░░██████ ██████▄░░░▀████▀░░▄██████ ▀██████▄░▄███▀░░░▄██████▀ ▀████▀▄████░░▄▄███████▀ ▀█▀▄████████████████▀ ▄████████████████▀░ ▀████████████▀▀░░░░ | | CCECASH | | | | ANN THREAD TUTORIAL |
|
|
|
|