اختراق SafePal يسرق العملات ويفتح بابًا لتسريب بيانات 40 ألف مستخدم

17 أغسطس 2026·اليوم السابع
اختراق SafePal يسرق العملات ويفتح بابًا لتسريب بيانات 40 ألف مستخدم

كشفت شركة SafePal التي توفر محافظ وأدوات لإدارة العملات المشفرة عن تسرب بيانات طلبات الشراء لنحو 40 ألف عميل، ولم يصل الاختراق إلى العملات أو مفاتيح المحافظ، لكنه كشف أسماء وعناوين وتفاصيل شراء يمكن أن تمنح المحتالين مادة شديدة الدقة لبناء رسائل انتحال تبدو مقنعة لأصحابها.

ثغرة في تتبع الطلبات


وفقًا لتقرير نشرته وكالة رويترز، سمح خلل في صلاحيات نظام تتبع الطلبات بالوصول إلى معلومات طلبات عملاء آخرين، وتأثر 39,798 مستخدمًا، بينما أكدت SafePal أن الحادث لم يشمل عبارات الاسترداد وهي الكلمات السرية التي تعيد فتح المحفظة، ولا المفاتيح الخاصة أو كلمات مرور المحافظ أو بيانات البطاقات والحسابات البنكية أو أرقام الهوية الحكومية، ما يعني أن الخطر المباشر على الأصول الرقمية ظل محدودًا.

الخطر يبدأ بعد التسريب


تكمن المشكلة في أن معرفة اسم العميل وعنوانه والمنتج الذي اشتراه تجعل رسالة التصيد أكثر واقعية، إذ يستطيع المهاجم انتحال صفة خدمة الدعم وطلب عبارة الاسترداد بحجة تحديث المحفظة أو تأمينها، وقالت SafePal إنها أصلحت الخلل وقررت الاحتفاظ ببيانات الطلبات مدة 90 يومًا فقط، كما رصدت وأغلقت أكثر من 30 موقعًا ورابطًا احتياليًا مرتبطًا بالحادث، وهي خطوة توضح أن التسريب تحول بالفعل إلى محاولات استغلال خارج النظام الأصلي.
 



SafePalcryptocurrenciesdata breach
الخبر متوفّر باللغات التالية:English
المصدر الأصلي للخبر
اليوم السابع

SafePal breach steals crypto, opens door for data leak of 40K users

August 17, 2026·Youm7
SafePal breach steals crypto, opens door for data leak of 40K users

SafePal, a company that provides cryptocurrency wallets and management tools, has revealed a data leak affecting the purchase orders of around 40,000 customers. The breach did not compromise any cryptocurrencies or wallet keys, but it exposed names, addresses, and purchase details that could provide highly targeted material for fraudsters to craft convincing phishing messages.

A Flaw in Order Tracking


According to a report by Reuters, a flaw in the order tracking system's permissions allowed access to information about other customers' orders. This affected 39,798 users. SafePal confirmed that the incident did not involve recovery phrases (the passwords that unlock wallets), private keys, wallet passwords, card and bank account data, or government identification numbers, meaning the direct risk to digital assets remained limited.

The Risk After the Leak


The issue lies in the fact that knowing a customer's name, address, and the product they purchased makes phishing messages more realistic. An attacker could impersonate support services and request the recovery phrase under the guise of updating or securing the wallet. SafePal said it has fixed the flaw and decided to keep order data for only 90 days. It also identified and blocked over 30 fraudulent websites and links related to the incident, demonstrating that the leak had indeed evolved into attempts at exploitation outside the original system.

SafePalcryptocurrenciesdata breach
This article is also available in:العربية
Original source article
Youm7