The SafePal breach has exposed the addresses, but the cryptocurrency remains secure, which could pose a more significant issue.

The SafePal breach has exposed the addresses, but the cryptocurrency remains secure, which could pose a more significant issue.

      SafePal, the hardware and software crypto wallet manufacturer supported by Binance, has reported a data breach that impacts approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026. The compromised records include order information such as names, physical addresses, and contact details. While this leak may seem minor compared to larger incidents this year, like ShinyHunters’ release of 45GB of Madison Square Garden data, the identity of the affected customers adds significance.

      On a positive note, SafePal asserts that no cryptocurrency funds were compromised, and sensitive information such as passwords, private keys, seed phrases, bank information, payment card numbers, and government-issued IDs remained secure. The integrity of wallet security was maintained, ensuring users' digital assets were not affected. For a company focusing on providing security, this distinction is crucial, and it's a point the firm will likely emphasize.

      The source of the breach was relatively commonplace. SafePal attributed the incident to an “authorization flaw” in a third-party plugin used for order tracking, which allowed attackers to access other customers' order details simply through manipulation of order numbers. This is an example of an insecure-direct-object-reference vulnerability, which should have been identified during an initial security review but was overlooked in an add-on tool.

      SafePal claims it fixed the flaw immediately and has contacted affected users from the address [email protected]. The company has also engaged an independent third-party auditor, reduced its data retention period to 90 days, identified and taken down over 30 fraudulent websites and phishing links, and provided customers with a way to verify if their information was included in the breach.

      In terms of breach response, SafePal's actions are orderly and notably quicker than the usual corporate hesitation that typically accompanies such disclosures. However, there is an uncomfortable reality: this crypto breach didn't compromise the cryptocurrency itself but leaked customers’ addresses, which may present a more severe risk for this particular demographic. While a postal address alone can't deplete a wallet, it can enable other detrimental actions.

      The immediate danger involves the familiar risks associated with targeted phishing and impersonation. Possessing names and contact details of nearly 40,000 crypto owners provides a convenient target for phishing schemes. Emails will appear credible because the sender knows what the recipient purchased and where it was sent.

      This issue ties into the social-engineering tactics employed by groups like those behind the Ryuk ransomware, which generated $3.7 million in Bitcoin for its operators. The lesser-known, yet more alarming risk pertains to physical safety. For known cryptocurrency holders, a leaked name linked to a home address raises the possibility of a “wrench attack”—a term that describes coercing an individual into surrendering their keys in person.

      Given the irreversibility and trace challenges of crypto transactions, the motive to visit someone’s home is substantial. Reports of targeted attacks, theft, and worse against crypto holders are on the rise, and having a list of confirmed owners with their delivery addresses is particularly concerning.

      Another predictable takeaway is that the weak point was not SafePal's security measures but rather a third-party plugin integrated with its system. This scenario has become a common factor in modern data breaches, similar to recent vulnerabilities that affected cosmetics giant Estée Lauder due to a flaw in Oracle E-Business: while the core system remained intact, the additional component did not.

      SafePal deserves recognition for its swift and transparent response, as well as for having a product where a breach of the storefront did not compromise the wallets. Still, this incident serves as a reminder that in the realm of crypto, privacy is not merely an added feature alongside security. For customers whose names and addresses are now publicly available and who cannot alter or secure their residential location, privacy is an essential aspect of security.

Other articles

The United States is poised to force its allies to choose a side in the AI cold war. The United States is poised to force its allies to choose a side in the AI cold war. A leaked letter from the State Department alerts 35 allied nations that they cannot participate in both American and Chinese AI initiatives, transforming the Pax Silica agreement into a measure of loyalty. The United States is on the verge of compelling its allies to choose a side in the AI cold war. The United States is on the verge of compelling its allies to choose a side in the AI cold war. A leaked letter from the State Department cautions 35 allied nations that they cannot participate in both American and Chinese AI initiatives, transforming the Pax Silica agreement into a test of loyalty. Stripe has allegedly acquired OpenRouter, the AI model routing technology, for more than $7 billion. Stripe has allegedly acquired OpenRouter, the AI model routing technology, for more than $7 billion. Stripe has supposedly completed an agreement to acquire OpenRouter, the AI platform that manages traffic for over 400 models, for more than $7 billion, betting that sustainable profits in AI lie in metering and billing. According to reports, Stripe has acquired OpenRouter, the AI model routing platform, for more than $7 billion. According to reports, Stripe has acquired OpenRouter, the AI model routing platform, for more than $7 billion. Stripe is said to have finalized a deal to acquire OpenRouter, the AI platform that directs traffic to over 400 models, for more than $7 billion. This move reflects a belief that sustainable revenue in AI lies in metering and billing. Robotic firms are transitioning into AI companies as AgiBot unveils the emerging dynamics of competition in embodied AI. Robotic firms are transitioning into AI companies as AgiBot unveils the emerging dynamics of competition in embodied AI. Reflecting on a few years ago, the competition among companies producing humanoid robots appeared fairly simple: the one that could create a robot had an opportunity to The vacation pictures you share may assist scammers in pinpointing your exact location. The vacation pictures you share may assist scammers in pinpointing your exact location. Artificial intelligence can detect locations from vacation pictures shared on Instagram and Facebook, which provides scammers with sufficient data to craft believable phishing messages related to travel and credit card activity.

The SafePal breach has exposed the addresses, but the cryptocurrency remains secure, which could pose a more significant issue.

SafePal, the cryptocurrency wallet manufacturer supported by Binance, has reported a security breach that has revealed the names and physical addresses of almost 40,000 customers, increasing the risks of phishing and physical attacks.