Techcrunch iconTechcrunchAug 17, 2026 ~3 min source read

Recent shipping-company breaches put hardware-wallet owners at higher risk of real-world attacks

Breaches at shipping partners exposed names, addresses, emails and phone numbers for customers of Trezor and SafePal. The leaks increase the threat of violent “wrench attacks” and targeted phishing, even though the devices themselves were not remotely compromised.

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

Share this story

Send the public story page.

Useful takeaways from this story.

Exposed personal data raises risk of physical attacks (wrench attacks) and targeted phishing, despite wallets remaining offline.

Separate incident: Coldcard/Coinkite wallets lost more than $130 million after attackers exploited a seed-generation/password vulnerability.

Customers should assume greater physical and phishing risk and take concrete steps to reduce exposure.

# What happened

The breaches did not compromise the wallets' offline cryptographic security. The devices remain designed to operate offline so they are harder to attack remotely. The problem is the supply chain: attackers targeted the vendors that handled shipping and customer data to learn where high-value crypto holders live.

# Why this matters now With names and home addresses in hand, criminals can mount real-world attacks aimed at forcing victims to reveal their seed phrases. These so-called wrench attacks use threats, kidnapping or home invasion to extract the secret recovery phrase that gives attackers irreversible access to funds on the public blockchain.

Security firms have reported an uptick in these kinds of incidents. CertiK confirmed dozens of reported wrench attacks in 2025 and recorded a 75% year-over-year increase, with robbers stealing upwards of $40 million. Chainalysis reported around $30 million stolen so far this year, including robberies where kidnappings and invasions were used to coerce victims into surrendering seed phrases.

# How attackers are likely to act

  • Physical attacks: With a physical address and a name, attackers can focus on home invasion, kidnapping or other coercive tactics to obtain seeds.
  • Supply-chain targeting: The breaches show attackers will go after third parties — shipping vendors, fulfillment partners — rather than attacking wallet vendors directly.

# Practical steps for affected customers

  • Treat communications with extra suspicion. Expect targeted phishing by phone and email and verify messages before acting.
  • Do not reveal seed phrases to anyone under any circumstances. No legitimate wallet vendor will request a seed phrase.
  • Strengthen physical security: consider alternate delivery options (P.O. box or trusted pickup), avoid advertising large holdings, and review home security if your address was exposed.
  • If you think you may be targeted, move funds to a wallet setup with stronger protections you control and consider professional security advice for high-value holdings.

# What to watch next

# Bottom line The immediate cryptographic security of most hardware wallets wasn't broken by these shipping-company leaks. The practical risk has risen because attackers can now link people to addresses and contact details, enabling violent coercion and highly targeted phishing. Wallet owners should assume increased risk and take concrete steps to reduce exposure and verify communications.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app