All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Crypto hardware wallet owners face new risks from data breaches

Created at 17 Aug · 1:31 PM1 source↑ Market-relevant
IN SHORT

Data breaches at shipping partners of crypto hardware wallet makers Trezor and SafePal have exposed customer personal information, increasing the risk of physical "wrench attacks." Separately, hackers exploited a vulnerability in Coinkite's Coldcard wallet to steal over $130 million.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

75%increase in reported wrench attacks in 2025
$40 millionstolen via wrench attacks in 2025
$30 millionstolen via wrench attacks so far this year
$130 millionstolen from Coinkite's Coldcard wallets

Who's Involved

Trezor
hardware crypto wallet maker reporting customer data theft
SafePal
hardware crypto wallet maker reporting customer data theft
CertiK
blockchain security company confirming rise in wrench attacks
Chainalysis
crypto forensics firm reporting on wrench attack figures
Coinkite
hardware wallet maker whose Coldcard product was exploited
Crypto hardware wallet owners face new risks from data breaches

↳ Why This Matters

The breaches expose cryptocurrency owners to physical threats and sophisticated exploits, underscoring the need for enhanced security measures beyond just the hardware wallet itself, including vigilance against phishing and awareness of supply chain risks.

Key facts

  • Data breaches at shipping companies for Trezor and SafePal exposed thousands of customers' personal data.
  • Stolen information includes names, home addresses, email addresses, and phone numbers.
  • These breaches increase the risk of physical "wrench attacks" targeting crypto owners.
  • Hackers stole over $130 million in cryptocurrency by exploiting a vulnerability in Coinkite's Coldcard hardware wallet.
  • The Coldcard exploit allowed hackers to predict seed phrases and access funds directly from the blockchain.

Recent data breaches at shipping partners of cryptocurrency hardware wallet manufacturers Trezor and SafePal have exposed personal data of thousands of customers, heightening the risk of physical "wrench attacks." The stolen information, including names and home addresses, could enable criminals to locate and coerce individuals into revealing their crypto seed phrases.

These breaches highlight vulnerabilities within the broader tech supply chain that supports the cryptocurrency industry. While the hardware wallets themselves remain secure offline, the personal data associated with their owners is now at risk. Blockchain security firm CertiK noted a 75% increase in reported wrench attacks in 2025, with criminals stealing significant sums through methods like kidnapping and home invasions to obtain seed phrases.

In a separate incident, hackers managed to steal over $130 million in cryptocurrency by exploiting a vulnerability in the code of Coinkite's Coldcard hardware wallet. Despite the wallet's offline nature, attackers were able to predict the seed phrases generated and access funds directly from the blockchain, demonstrating a sophisticated attack vector that bypassed traditional security measures.

Frequently asked questions

Personal data including customer names, home addresses, email addresses, and phone numbers were stolen from shipping partners of Trezor and SafePal.

The stolen personal information can be used to identify and locate high-net-worth crypto holders, making them targets for physical "wrench attacks" to steal their seed phrases.

Hackers exploited a vulnerability in the Coldcard wallet's code to predict customer seed phrases, allowing them to steal over $130 million in cryptocurrency directly from the blockchain.

The hardware wallets themselves remain secure offline. However, the associated personal data and potential software vulnerabilities can still be exploited.

What Happens Next

01Customers are advised to remain vigilant against phishing attempts.
02Users are warned about potential physical attacks targeting their crypto holdings.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Trezor and SafePal reported data breaches at their shipping partners.
Customer names, addresses, emails, and phone numbers were stolen.
The breaches increase the risk of physical "wrench attacks" on crypto owners.
Hackers stole over $130 million from Coinkite's Coldcard hardware wallets.
The Coldcard hack exploited a vulnerability in the wallet's seed phrase generation.

Sources

T1
Crypto hardware wallet owners face fresh security risks after recent spate of personal data theftsTechCrunch

Related Stories

Coldcard bug led to $100M in Bitcoin hacks
17 Aug · 2:06 PM
Bits of Gold data breach affects 200,000 customers
17 Aug · 12:11 PM
Binance Shared Russian Client Data Used in Terrorism Financing Charges
17 Aug · 6:07 AM
Harmony to Roll Back Blockchain After Exploit, Discarding 109,000 Transactions
17 Aug · 12:45 PM
Bitcoin Holders Bet on Fixed Supply Over Price Swings
17 Aug · 11:36 AM