News

Global security awareness — not only PulseChain.

Permalink for this incident. Same content as the News feed — use Share to post it.

Cross-chain security awareness in plain English. Not an audit. Not financial advice. We never publish drain recipes or exploit steps. News items are research snapshots from public reporting — not always a full 369 deep-dive.

highCustody / hardwarephishing

SafePal: order-tracking plugin exposed ~39.8k customers’ PII

16 Aug 2026: SafePal disclosed an authorization flaw in an order-tracking plugin. Under some conditions another customer’s order could be read. About 39,798 customers who ordered between 2 Mar 2025 and 11 Apr 2026 had name, email, shipping address, phone, and purchase details accessed externally. Vendor states seed phrases, private keys, wallet passwords, bank/card data, and government IDs were not in this set; cold storage is separate from the shop servers. Issue remediated; third-party review engaged; affected customers emailed from security@safepal.com. Real risk is targeted phishing (fake support, firmware, refund, delivery). Same class as the Trezor/ShipMonk shipping PII incident — not a protocol drain and not the Coldcard seed-entropy sweep.

369 take: A hardware wallet can still be “fine” while the shop that mailed it leaks enough PII for convincing fake-support plays. Never type a seed or backup into a site, app, or phone call that arrived after a vendor email. Check status only on the official SafePal security-update page. Pulse lesson: treat any wallet-vendor or logistics PII leak as phishing season for that cohort, not as proof the device itself was emptied.