LIVE · cybersecurity feed
Live wire
breach

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.

zeroday.news ·

SafePal, a manufacturer of cryptocurrency hardware wallets, has confirmed a data breach affecting nearly 40,000 customers. The company disclosed on Sunday that personal information of individuals who placed orders between March 2, 2025, and April 11, 2026, was compromised. Stolen data includes names, email addresses, shipping addresses, phone numbers, and purchase specifics.

The breach stemmed from a flaw identified in the order-tracking function of a plug-in used for customer order information. SafePal stated that under specific conditions, this vulnerability allowed unauthorized access to other customers' order details. The company has since remediated the issue. SafePal emphasized that the security of its hardware wallets, seed phrases, and private keys remains unaffected.

All impacted customers have received email notifications, and SafePal has established a website where users can verify if their information was compromised. The company issued a warning that affected individuals are likely targets for sophisticated phishing attempts, which may include fraudulent phone calls, emails, text messages, fake refund offers, and deceptive customer support communications.

This incident follows recent security issues at other hardware wallet manufacturers, including Trezor and Coinkite, which also saw customer data exposed. A hacker reportedly advertised information allegedly stolen from SafePal on a dark web cybercriminal forum.

Data breaches involving cryptocurrency holders are particularly concerning due to the risk of "wrench attacks," a term for violent, in-person incidents where individuals are coerced into surrendering their digital assets. According to blockchain security audit firm CertiK, the first half of 2026 has seen a 33% year-over-year increase in such attacks, with 52 incidents reported globally through June, up from 39 in the same period of 2025. Losses from these attacks have reached $124 million this year, a significant increase from $10.5 million in the first half of 2025.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequ

breach

Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.

vulnerability

An AI broke Snowflake's code. Then another AI agent exploited it

Don't worry, this one was via a bug bounty program

ai

Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.

vulnerability

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

UNISOC modem flaw enabled kernel-level code execution through video calls

CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe