SafePal Data Breach Exposes Nearly 40,000 Customers to Phishing Risk
Hardware wallet maker SafePal has confirmed that a security flaw in a third-party plugin used to track customer orders allowed unauthorized parties to access personal data belonging to 39,798 customers. The company says the exposure occurred over an extended period, giving attackers a long window to collect information before the issue was identified.
SafePal has warned affected users that the exposed data could be used to craft convincing phishing emails or fraudulent phone calls, particularly dangerous given the company's role in cryptocurrency security. Attackers often use breached order or contact details to impersonate legitimate businesses and trick victims into revealing sensitive information such as passwords, recovery phrases, or payment details.
While this incident involves a large hardware wallet provider, it highlights a risk relevant to any small business using third-party plugins or apps to manage orders and customer data: a single flawed integration can expose customer information well beyond what the business intended to share. Regularly auditing third-party tools and promptly patching or disabling faulty plugins can reduce this risk.