AI Security AI安全 3d ago Updated 3d ago 更新于 3天前 42

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers SafePal硬件钱包制造商称漏洞导致近4万客户数据泄露

SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed personal data (names, emails, shipping addresses, phone numbers, purchase details) of approximately 39,798 customers The breach did not compromise wallet credentials, private keys, seed phrases, or financial information, but exposed PII that enables targeted phishing and social engineering attacks A configuration error caused a data-cleanup process to fail between September 2025 and April 2026, extending the affect SafePal硬件钱包制造商披露授权漏洞,导致约39,798名客户的个人信息(姓名、邮箱、地址、电话、购买详情)被泄露 漏洞存在于订单跟踪插件中,不涉及钱包凭证、私钥或财务信息,无证据表明钱包或资金被入侵 受影响订单时间为2025年3月2日至2026年4月11日,安全团队5月初收到报告但延迟至8月才正式确认 威胁行为者已在网络犯罪论坛发布数据集,SafePal已修复漏洞并实施多项补救措施

65
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed personal data (names, emails, shipping addresses, phone numbers, purchase details) of approximately 39,798 customers
  • The breach did not compromise wallet credentials, private keys, seed phrases, or financial information, but exposed PII that enables targeted phishing and social engineering attacks
  • A configuration error caused a data-cleanup process to fail between September 2025 and April 2026, extending the affected order window back to March 2025
  • SafePal initially treated the first report in early May 2026 as isolated, delaying formal investigation and public disclosure until August 2026
  • A threat actor has advertised the stolen dataset on a cybercrime forum, offering verification tools for prospective buyers

Why It Matters

This incident highlights the critical importance of timely security incident response and transparent communication in the cryptocurrency hardware wallet space, where customer trust is paramount. The breach demonstrates how seemingly benign order-tracking vulnerabilities can cascade into significant privacy risks, especially when combined with poor data retention practices. For the broader crypto industry, it reinforces the growing threat landscape where stolen PII is weaponized for targeted social engineering against high-value crypto holders.

Technical Details

  • Vulnerability Type: Authorization flaw in an order-tracking plug-in allowing unauthorized access to another customer's order information; no CVE identifier assigned, and the specific plug-in vendor/version was not disclosed
  • Data Exposure Scope: Approximately 39,798 customer records spanning orders placed between March 2, 2025, and April 11, 2026; exposed data includes names, email addresses, shipping addresses, phone numbers, and purchase details
  • Root Cause: A configuration error caused a scheduled data-cleanup process to stop working correctly between September 2025 and April 2026, leaving older order records in the system longer than intended
  • Remediation Measures: Fixed the authorization flaw, reduced personal information retention to 90 days, purged affected records from active servers (keeping secured offline backup for investigations), engaged independent third-party security firm for validation, contacted third-party logistics partners, and taken down over 30 fraudulent websites/phishing links
  • Detection Timeline: First report received in early May 2026 was initially treated as isolated; full review and rebuild of order-processing pipeline began in July 2026, with root cause confirmed during that work; public disclosure occurred on August 16, 2026

Industry Insight

  • Data Retention as Security Control: SafePal's incident contrasts sharply with Trezor's approach, which credited a 90-day data storage policy for limiting exposure during a separate shipping provider breach—demonstrating that minimal data retention is a proven defensive strategy worth adopting industry-wide
  • Response Time Vulnerabilities: The three-month gap between initial detection (May 2026) and public disclosure (August 2026) underscores the risk of treating security reports as isolated incidents; organizations should establish clear escalation thresholds and mandatory investigation protocols for any unauthorized access indicator
  • Threat Actor Monetization Patterns: The rapid appearance of the stolen dataset on cybercrime forums with verification tools indicates sophisticated threat actor operations; companies should anticipate data resale and prepare proactive customer communication about verification mechanisms and phishing awareness, as demonstrated by the Ledger breach aftermath which showed spam, scams, and device tampering among affected customers

TL;DR

  • SafePal硬件钱包制造商披露授权漏洞,导致约39,798名客户的个人信息(姓名、邮箱、地址、电话、购买详情)被泄露
  • 漏洞存在于订单跟踪插件中,不涉及钱包凭证、私钥或财务信息,无证据表明钱包或资金被入侵
  • 受影响订单时间为2025年3月2日至2026年4月11日,安全团队5月初收到报告但延迟至8月才正式确认
  • 威胁行为者已在网络犯罪论坛发布数据集,SafePal已修复漏洞并实施多项补救措施

为什么值得看

本文揭示了硬件钱包行业供应链安全的关键风险,第三方插件漏洞可直接导致大量用户个人信息泄露。事件反映了加密货币硬件钱包厂商在数据保护和漏洞响应方面的不足,对行业安全实践具有重要警示意义。

技术解析

  • 漏洞类型:订单跟踪插件存在授权缺陷,允许未授权访问其他客户的订单信息,但未披露具体插件名称、供应商或版本,也未分配CVE编号
  • 数据泄露范围:泄露数据包含姓名、邮箱、收货地址、电话号码和购买详情,明确排除了钱包凭证、私钥、密码、银行账户、支付卡号等敏感财务信息
  • 时间线问题:受影响订单跨度约13个月,但漏洞可利用时间未明确;首次报告于2026年5月初,正式确认延迟至8月,存在约3个月的响应间隔
  • 补救措施:数据保留期限缩短至90天,已清除活跃服务器中的受影响记录,聘请独立第三方安全公司验证修复方案,联系第三方物流合作伙伴确认漏洞未扩散,已下线30余个钓鱼网站

行业启示

  • 供应链安全需强化:硬件钱包厂商高度依赖第三方插件和物流服务商,供应链任一环节的安全漏洞都可能导致大规模数据泄露,需建立严格的第三方安全审计机制
  • 漏洞响应时效性不足:从首次报告到正式确认耗时3个月,暴露了安全事件响应流程的滞后,行业应建立更快速的漏洞验证和披露机制
  • 数据最小化原则至关重要:Trezor因90天数据保留政策限制了泄露影响,而SafePal因数据清理流程故障导致数据长期留存,凸显了数据保留策略对降低安全风险的关键作用

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全