A vulnerability in an order-tracking plug-in used by hardware wallet maker SafePal has exposed the personal details of nearly 40,000 customers, raising alarm across the crypto community about the growing threat of physical attacks against digital asset holders.
What Happened
The breach stemmed from a flaw in a third-party plug-in that SafePal used to let customers track their shipments. According to reports, the vulnerability left sensitive information accessible, including customer names, home addresses and phone numbers.
Roughly 40,000 individuals are believed to have been affected. Because the exposed data ties real-world identities and locations to people who purchased cryptocurrency hardware wallets, security researchers say the incident is especially dangerous.
Hardware wallets are marketed as a way to keep crypto holdings offline and out of reach of hackers. But a data leak that connects a person's name and home address to their status as a wallet owner undermines that protection in a different way.
A leaked address book of crypto owners is exactly the kind of shopping list that criminals crave.
Fears of Physical Attacks
The crypto industry has seen a rise in so-called "wrench attacks," in which criminals target holders in person, using threats or violence to force victims to hand over their assets. Breaches that reveal who owns crypto and where they live can fuel that kind of crime.
Concerns are heightened because the compromised data points specifically to people who bought devices designed to store significant holdings offline. Attackers could potentially use the information to identify and locate targets.
Security experts generally recommend that crypto holders take several precautions in the wake of such leaks:
- Stay alert to phishing calls and messages referencing recent orders
- Avoid publicly discussing crypto holdings or hardware purchases
- Consider updating shipping and contact information where possible
The incident adds to a string of data exposures affecting the crypto sector and underscores the risks that arise when companies rely on third-party tools to handle sensitive customer information.
