Introduction
Recent data breaches at two shipping companies have heightened the risk of fund theft for cryptocurrency owners using physical hardware wallets, exposing critical vulnerabilities in the broader tech ecosystem that the crypto industry relies on.
Breach Details
In recent weeks, hardware wallet manufacturers Trezor and SafePal reported that thousands of their customers had personal and shipping information stolen during separate data breaches at their shipping partners. The wallet makers had provided customers' names, home addresses, email addresses, and phone numbers to these shipping companies for product delivery.
Impact on Wallet Security
The hacks did not compromise the security of the hardware wallets themselves—devices that remain offline to thwart remote cyberattacks. Instead, attackers targeted the supply chain to obtain personal details about where high-net-worth crypto holders reside. By stealing names and home addresses, the breaches expose owners to physical attacks, where criminals might force victims to reveal their seed phrases through violence or intimidation.
Rise of Wrench Attacks
These real-world attacks, often called "wrench attacks" due to the potential use of weapons, are on the rise. Blockchain security firm CertiK documented dozens of such attacks in 2025, up 75% from the previous year, with losses exceeding $40 million. In 2026, crypto forensics firm Chainalysis estimates losses at nearly $30 million so far, with gangs employing kidnapping and home invasions to extract seed phrases.
Once attackers obtain a seed phrase, they can irrevocably take control of the victim's crypto on the public blockchain. Both Trezor and SafePal have urged customers to remain vigilant against phishing attacks, which use targeted messages via phone or email to steal funds.
Separate Hardware Wallet Exploit
In a separate incident earlier this month, hackers stole over $130 million in cryptocurrency by exploiting a vulnerability in Coinkite's Coldcard hardware wallet. The attackers, still unidentified, predicted seed phrases generated offline by Coldcard devices, allowing them to drain funds directly from the blockchain. Despite the wallets never being connected to the internet, a flaw in a 2021 code line enabled the attack.
One victim posted on X, lamenting that they had "done everything right," but "none of it mattered… all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability."
Conclusion
These incidents underscore the need for enhanced security across the entire crypto supply chain, including shipping and hardware manufacturing, as well as increased awareness among users about the growing threat of physical attacks and firmware vulnerabilities.
via TechCrunch
