
Revolut says a limited number of customers were affected after fake government requests exposed sensitive data.
SafePal says a vulnerability involving order information exposed customer data tied to hardware wallet purchases, while warning affected users about more sophisticated phishing attempts.

SafePal said it recently found and fixed a vulnerability in a system containing users’ order information. According to the report, unauthorized access exposed data for 39,798 customers who placed orders from March 2 of last year to April 11 of this year. The issue involved order information, not a reported theft of cryptocurrency.
The exposed information includes names, email addresses, shipping addresses, phone numbers, and purchase details, according to SafePal. The company said SafePal wallets, seed phrases, and private keys are secure. That distinction matters because the immediate risk described is not direct wallet compromise, but misuse of customer information.
SafePal warned that affected customers might face more sophisticated phishing attempts. Attackers with contact details and purchase information could use real names, locations, or order context to make scams feel more convincing. Users should treat unexpected messages about wallets, seed phrases, private keys, or account security as high-risk and avoid sharing sensitive wallet information.
Hardware wallets are designed to help protect crypto assets, but customer records around those purchases can still create security exposure. The SafePal incident shows why buyers should separate device security from personal-data security. Even when keys remain secure, leaked contact and purchase details can increase the chance of targeted social engineering.

Revolut says a limited number of customers were affected after fake government requests exposed sensitive data.

A Brevo breach let attackers send phishing emails to Trezor customers.

Chrome now ships updates every two weeks to move security fixes and features faster.

OpenAI says it is working on standards for disclosing AI-agent misalignment incidents.