🫢 SafePal recently notified 39,798 customers about a data breach but the problem wasn’t the hardware wallet itself. It came from a third-party shipping-order plug-in that exposed customer order information, including names, addresses and contact details.
⌛ No seed phrases, private keys or funds were compromised. But knowing someone owns a hardware wallet and knowing exactly where it was delivered can still create a serious phishing and social-engineering risk.
💡 SafePal has since patched the issue, brought in external auditors and is reducing how long customer data is stored. The bigger lesson? Security isn’t only about protecting private keys. Every extra service connected to a product can create another point of exposure.
💲 BoBe takes a different approach to custody: we don’t hold users’ funds or private keys. Your assets remain in your own wallet while you interact with BoBe through smart contracts.
💭 What would you do if your hardware wallet purchase - including your home address - ended up in someone else’s hands?
