Key facts
- Data breaches at shipping companies for Trezor and SafePal exposed thousands of customers' personal data.
- Stolen information includes names, home addresses, email addresses, and phone numbers.
- These breaches increase the risk of physical "wrench attacks" targeting crypto owners.
- Hackers stole over $130 million in cryptocurrency by exploiting a vulnerability in Coinkite's Coldcard hardware wallet.
- The Coldcard exploit allowed hackers to predict seed phrases and access funds directly from the blockchain.
Recent data breaches at shipping partners of cryptocurrency hardware wallet manufacturers Trezor and SafePal have exposed personal data of thousands of customers, heightening the risk of physical "wrench attacks." The stolen information, including names and home addresses, could enable criminals to locate and coerce individuals into revealing their crypto seed phrases.
These breaches highlight vulnerabilities within the broader tech supply chain that supports the cryptocurrency industry. While the hardware wallets themselves remain secure offline, the personal data associated with their owners is now at risk. Blockchain security firm CertiK noted a 75% increase in reported wrench attacks in 2025, with criminals stealing significant sums through methods like kidnapping and home invasions to obtain seed phrases.
In a separate incident, hackers managed to steal over $130 million in cryptocurrency by exploiting a vulnerability in the code of Coinkite's Coldcard hardware wallet. Despite the wallet's offline nature, attackers were able to predict the seed phrases generated and access funds directly from the blockchain, demonstrating a sophisticated attack vector that bypassed traditional security measures.
