An authorization flaw in SafePal’s order-tracking system exposed personal information from approximately 40,000 customers, including names, email addresses, shipping addresses, phone numbers, and purchase details. A configuration error prevented scheduled data deletion between September 2025 and April 2026. Private keys and recovery phrases were not compromised. This breach is part of a wave of security incidents targeting hardware wallet providers: Trezor was also hit through its shipping provider, and Coldcard suffered losses exceeding $100 million in Bitcoin. The exposed data increases the risk of targeted phishing and physical attacks against identifiable crypto holders.
Source: Read the original article

