A Vulnerability in SafePal Hardware Wallets Exposed Personal Data of Thousands
SafePal, a Singapore-based company that produces hardware wallets for cryptocurrency users, has disclosed a critical security flaw that exposed sensitive information about nearly 40,000 customers. The vulnerability, discovered by an anonymous researcher and reported to SafePal through their bug bounty program, allowed attackers to access the personal data stored on affected devices.
The exploit worked by manipulating the wallet’s firmware, which is responsible for encrypting and storing user data. By tampering with the firmware, hackers could gain unauthorized access to sensitive information such as names, email addresses, and even private keys used to secure cryptocurrency transactions. This level of access would have enabled attackers to drain affected wallets or launch more sophisticated social engineering attacks against users.
SafePal’s security team confirmed that the flaw was present in all versions of their hardware wallets produced since 2020, including popular models such as the SafePal S1 and SPW10. The company has since released a firmware update that patches the vulnerability and recommends that affected users install it immediately to prevent potential attacks.
The exposed data is particularly concerning because it includes sensitive information that could be used for phishing or identity theft. Cryptocurrency users are often targeted by sophisticated attackers who use social engineering tactics to trick them into revealing their private keys or other sensitive information. With access to this type of data, hackers would have a significant advantage in launching such attacks.
The incident highlights the need for hardware wallet manufacturers to prioritize security and regularly test their products against potential vulnerabilities. SafePal’s response to the issue has been swift, but it also underscores the importance of user vigilance when dealing with sensitive financial information. To protect yourself from similar threats, always keep your software up-to-date, use strong passwords or passphrases, and be cautious of unsolicited emails or messages that request sensitive information.
In this case, SafePal’s prompt response to the issue is a welcome sign, but it also serves as a reminder for users to stay informed about potential security risks and take proactive steps to protect themselves.
Source: The Hacker News — 2026-08-18