Data breaches at two shipping companies have put cryptocurrency owners who use physical hardware wallets at greater risk of having their funds stolen — not online, but in the real world.
Trezor and SafePal, two of the biggest hardware-wallet makers, recently reported that personal data and shipping information for thousands of customers were stolen in separate breaches at the shipping partners they use to mail out devices. The exposed records included names, home addresses, email addresses and phone numbers.
The hacks did not compromise the wallets themselves — offline devices designed to protect crypto from internet-based attacks. Instead, the thieves now know where crypto holders live, opening the door to so-called wrench attacks: violent robberies in which attackers force victims to hand over the seed phrase that unlocks their funds.
These physical attacks are on the rise. Blockchain security firm CertiK counted dozens of reported wrench attacks in 2025, up 75% from the previous year, with robbers stealing more than $40 million. Crypto forensics firm Chainalysis puts this year's haul at close to $30 million so far, with gangs using kidnappings and home invasions to demand seed phrases.
The shipping breaches are the latest in a grim stretch for hardware wallets. Earlier this month, hackers stole more than $130 million in cryptocurrency directly off the blockchain by exploiting a vulnerability in Coinkite's Coldcard wallet: a flaw in the code that generated seed phrases let attackers predict the phrases wallets would create offline and drain the funds, even though the wallets themselves never touched the internet. One victim wrote on X that they had done "everything right," but that "none of it mattered... all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability."
Both Trezor and SafePal also warned customers to stay vigilant against phishing messages targeting the leaked phone numbers and email addresses. A stolen wallet can be replaced, security researchers note — but a leaked home address is not something a firmware update can fix.
Sources
- techcrunch.comCrypto hardware wallet owners face fresh security risks after recent spate of personal data thefts — TechCrunch
- reuters.comCrypto wallet provider SafePal discloses data breach affecting nearly 40,000 — Reuters
- trmlabs.comThe Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack — TRM Labs




