🚨 Security Alert | SafePal User Data Exposure
SafePal disclosed an authorization flaw in a third-party order-tracking plugin that could allow unauthorized access to other users’ order information.
👤Approximately 39,798 users were affected. Exposed data may include names, email addresses, shipping addresses, phone numbers, and purchase details.
SafePal says seed phrases, private keys, wallet passwords, and payment information were not compromised, and there is currently no evidence that the incident directly resulted in asset theft.
🛡️But for crypto users, the risk does not end there.
Real identity and purchase data can be used to create highly convincing targeted phishing campaigns, including fake SafePal support messages📨, refund notices⚠️, firmware updates, or 👝wallet verification requests:
Authorization flaw → User data exposure → Targeted phishing → Seed phrase / credential theft → Asset loss
💡Security Takeaway
Even if a wallet and its private keys remain secure, data leaks from surrounding systems can still put user assets at risk.
If you receive SafePal-related support, refund, or wallet verification messages, verify them through official channels. ‼️Do not click unfamiliar links, and never share your seed phrase or private key with any website or support agent.