The crypto wallet company SafePal <a href="https://www.safepal.com/en/blog/security-update” rel=”nofollow noopener” target=”_blank”>said on Sunday that it had “recently” found and fixed a vulnerability in a system containing users’ order information, and that, if exploited, this would have allowed potential attackers to access said information. But it added that apparently someone did access it without authorization, exposing the data of customers who placed orders from March 2 of last year to April 11 of this year.
SafePal customers probably understand this intuitively, but outsiders might not: this doesn’t mean anyone’s crypto was stolen or directly jeopardized. Like Ledger, which notified users of a third-party data breach earlier this year, SafePal makes hardware wallets, which are usually thin little gadgets that look like a mix between a credit card and a tiny smartphone. What was exposed was the identifying information of 39,798 people who likely bought SafePal devices.
SafePal says the exposed data includes, “name, email address, shipping address, phone number, and purchase details.”
https://x.com/SafePal/status/2088937173139812792
Hardware wallets like SafePal’s are, funnily enough, supposed to be safeguards. They’re air-gapped, and therefore theoretically un-hackable resources for sequestering the crucial information needed to perform blockchain transactions. In other words, your phone or computer can be hacked to high heaven, but if you have a hardware wallet—and excellent security hygiene—at least your crypto will stay safe.
So given that SafePal customers’ actual crypto is still locked up, the issue is that, as SafePal notes, “affected customers might be targeted by more sophisticated phishing attempts.” This phishing possibility is evidently a big deal for SafePal, because the FAQ page for users potentially exposed in this breach has a giant warning about phishing at the top, featuring the hashtag #BewareOfPhishing.
Think about it: someone might have the phone numbers and email addresses of 39,798 people who own enough crypto to buy hardware wallets, and those wallets themselves are the keys to all those potential fortunes. It follows that with a little social engineering, customized perhaps with real names and a bit of regional specificity, attackers probably think they can pry those holdings out of at least a handful out of thousands of targets.
Such an attack would be easier—or at least less bloody—than what’s sometimes known as a “$5 wrench attack,” an increasingly prominent form of crime in which an attacker wielding a blunt object, or more likely a gun, shows up and demands the key info that unlocks your crypto.
Stay, uh, safe out there, pals.
