#SafePal Data Leak Risk
SafePal Breach Exposes 40k Records Amid Coldcard Hack Fears
WooFun2026-08-16 22:13
Key Takeaways
SafePal disclosed an authorization flaw exposing order data for nearly 40,000 customers. While crypto assets remain secure, the incident highlights phishing risks and follows a major Coldcard hack, urging users to diversify storage solutions.
Woofun AI reports that SafePal has disclosed a security incident exposing personal information for thousands of customers, occurring shortly after a significant hack of Coldcard hardware wallets. This event underscores the persistent vulnerabilities in crypto-storage infrastructure despite robust asset protection measures.
The breach originated from an "authorization flaw" within a plug-in designed to track customer orders, which allowed unauthorized access to other users' order details. This vulnerability was exploited to access data for 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The mechanism functioned similarly to a parcel-tracking system where altering an order number revealed another customer's receipt and delivery details.
Woofun AI data shows, exposed data included names, physical addresses, and contact details, creating significant risks for phishing and impersonation attacks.
Notably, cryptocurrency funds, passwords, private wallet keys, seed phrases, bank passwords, bank account information, payment card numbers, and government-issued IDs remained uncompromised. This stands in contrast to the recent Coldcard hack, where attackers reportedly stole at least $120 million in bitcoin, highlighting that while SafePal's core wallet security held, peripheral systems remain vulnerable.
Users who have shared private keys or seed phrases via a phishing email, phone call, or letter should treat their wallet as compromised and transfer their assets to a new wallet. This incident validates the need to assess concentration risk and diversify both crypto holdings and the wallets used to store them. Relying on a single storage solution continues to present unacceptable exposure to systemic and targeted threats.
Comments
No comments yet.