SafePal Leak Hits 40,000 Users as Hardware Wallet Threats Escalate to $100M Theft

Key Takeaways

SafePal disclosed a breach exposing 40,000 customer records due to authorization and configuration flaws. This incident joins a trend of hardware wallet vulnerabilities, including Coldcard’s $100 million theft, highlighting risks beyond private key secu

Woofun AI reports that SafePal has disclosed a significant data breach affecting 40,000 customers, marking a critical escalation in hardware wallet security threats. The incident stems from systemic failures within the company's order-tracking infrastructure rather than direct cryptographic compromise.

An authorization flaw permitted unauthorized access to records for purchases made between March 2, 2025, and April 11, 2026. Exposed data included names, email addresses, shipping addresses, phone numbers, and purchase details.

Structurally, a separate configuration error prevented a scheduled cleanup process from operating correctly between September 2025 and April 2026. This failure left older order records in the system, extending the affected dataset back to March 2025. Per Woofun AI, the combination of these failures explains why nearly 40,000 records remained accessible: one control failed to restrict access, while another failed to delete information that should no longer have been stored.

The deeper driver is the expansion of risk vectors beyond private keys. While incidents involving Trezor, Ledger, and SafePal have primarily exposed customer databases, Coldcard users have already suffered more than $100 million in direct Bitcoin theft. Security experts warn that stolen data enables targeted phishing, impersonation, and potentially physical attacks.

Notably, SafePal issued a similar warning after its own breach and said it had already taken down more than 30 fraudulent websites and phishing links targeting customers.

Taken together, these incidents complicate the idea of hardware wallets as a single line of defense. The devices may protect private keys, but users remain exposed to firmware failures, customer databases, and the broader infrastructure surrounding self-custody. This marks a shift where physical security is no longer the sole determinant of asset safety.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions