SafePal breach exposes 39,798 crypto wallet customers to credential theft
Hardware wallet provider confirms exploit of system flaw; stolen order data now advertised for sale by threat actor on underground markets.
SafePal, a cryptocurrency hardware wallet provider, disclosed a data breach affecting approximately 39,798 customers after an attacker exploited a vulnerability to extract customer order information. The company has confirmed the incident and warned affected users that their data is now being offered for sale by a threat actor.
The breach centers on customer order records, which typically include names, shipping addresses, email addresses, and phone numbers. While SafePal has not disclosed the technical nature of the flaw exploited, the company confirmed that the vulnerability allowed unauthorized access to its customer database. The threat actor is actively advertising the stolen dataset on underground forums, raising the risk of follow-on phishing campaigns and targeted social engineering attacks against cryptocurrency holders.
SafePal's customer base consists primarily of individuals holding digital assets, making the exposed data particularly valuable to attackers. Cryptocurrency users are frequent targets of sophisticated phishing schemes designed to trick victims into revealing seed phrases or private keys. The breach does not appear to have compromised wallet security directly, but the exposure of customer identities creates a vector for credential harvesting and account takeover attempts.
- 01Affected customers face elevated phishing and social engineering risk targeting crypto holdings
- 02SafePal's reputation among security-conscious crypto users may erode without transparent remediation
- 03Competitors may face scrutiny over their own customer data protection practices
- 04Law enforcement agencies tracking crypto-related cybercrime gain new dataset for attribution
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.