Hardware wallet provider SafePal disclosed on Aug. 16 a data breach tied to an authorization flaw in a third-party order-tracking plugin. The unauthorized access exposed order information for roughly 40,000 customers, including names, shipping addresses, phone numbers and order details. The company said it identified and took down more than 30 fraudulent websites and phishing links connected to the breach. SafePal stated that private keys, seed phrases and wallet funds were not affected. Some coverage noted the firm first learned of the issue in May, about three months before going public.
The Block, Reuters