Crypto Hardware Wallet Owners at Risk After Shipping Company Breaches Expose Customer Data

Data breaches at two shipping companies have put cryptocurrency hardware wallet owners at heightened risk of physical theft and fraud, exposing weaknesses in the supply chain relied on by the crypto industry.

In recent weeks, hardware wallet makers Trezor and SafePal disclosed that thousands of their customers had personal data stolen through separate breaches at their respective shipping partners. The compromised information included customers’ names, home addresses, email addresses, and phone numbers — data the wallet makers had shared with shipping companies to fulfill hardware orders.

The breaches did not affect the wallets themselves, which store cryptocurrency offline to limit exposure to internet-based attacks. Instead, hackers targeted the shipping companies to identify where high-net-worth crypto holders live, potentially enabling so-called wrench attacks — real-world, physically coercive attempts to force victims into handing over their crypto seed phrases.

Such attacks are increasing. Blockchain security company CertiK recorded dozens of wrench attacks during 2025, a 75% rise over the prior year, with thieves stealing more than $40 million. Crypto forensics firm Chainalysis puts losses from similar incidents so far this year at approximately $30 million, with methods including kidnapping and home invasions. A stolen seed phrase gives attackers irreversible control over a victim’s crypto holdings on the public blockchain. Both Trezor and SafePal also warned customers to watch for phishing attempts targeting their stolen contact details.

In a separate incident earlier in August 2026, hackers stole more than $130 million in cryptocurrency from users of Coinkite’s Coldcard hardware wallet by exploiting a code vulnerability dating to 2021. The flaw allowed attackers to predict the seed phrases the wallets generated offline, enabling them to access funds directly on the blockchain without ever touching the physical devices. One victim said on X that they had “done everything right” but that a single vulnerable line of code had made those precautions irrelevant.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top