01 logo

Crypto Hardware Wallet Data Breaches Expose Owners to Physical Attacks and Theft

Recent hacks at shipping partners of Trezor and SafePal have leaked customer names and addresses, fueling a surge in "wrench attacks" as criminals target high-net-worth crypto holders through home invasions and kidnapping.

By Mark Lim Published 25 days ago 7 min read

Data breaches at two shipping companies have put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry. The breaches have exposed thousands of customers to the threat of physical attacks, as criminals increasingly target high-net-worth individuals through home invasions, kidnapping, and other violent methods.

In recent weeks, makers of hardware crypto wallets Trezor and SafePal reported that collectively thousands of their customers had their personal data and shipping information stolen during separate data breaches at their shipping partners. The crypto wallet makers provided their customers' names, home addresses, email addresses, and phone numbers to the shipping companies for mailing out their hardware wallets.


The Nature of the Breaches

The hacks did not affect the security of the wallets themselves a hardware device that stays offline to make it far more difficult for hackers to compromise it over the internet. Instead, the hackers targeted the broader supply chain of tech companies to obtain personal information about where high-net-worth crypto holders live.

By stealing the names and home addresses of hardware wallet customers, the hacks expose crypto owners to physical attacks that rely on physically obtaining the seed phrase stored on the wallet by force or violence. This type of attack, known as a "wrench attack," represents a growing threat to crypto owners who have invested significant sums in digital assets.

The breaches underscore a fundamental vulnerability in the crypto ecosystem: while blockchain technology itself is highly secure, the humans who use it are not. The supply chain of crypto hardware wallets involves multiple third parties, each of which represents a potential point of failure. In this case, the shipping partners responsible for delivering the wallets to customers became the weak link.


The Rise of Wrench Attacks

Known as wrench attacks referring to the use of weapons these kinds of real-world attacks are on the rise as criminals increasingly seek out crypto belonging to high-net-worth individuals. Blockchain security company CertiK confirmed dozens of reported wrench attacks during 2025, up by 75% on the previous year, with robbers stealing upwards of $40 million. Crypto forensics giant Chainalysis puts this year's figures at closer to $30 million so far, with gangs using kidnapping and home invasions to demand a person's crypto seed phrase.

With knowledge of a person's seed phrase, the attackers can irreversibly take control of the person's crypto on the public blockchain. Unlike traditional banking, where stolen funds can often be recovered through fraud prevention measures, crypto transactions are irreversible and anonymous, making them an attractive target for criminals.

The rise in wrench attacks reflects the growing value of cryptocurrency and the increasing sophistication of criminal networks. As crypto has become more mainstream, criminals have adapted their tactics to target the individuals who hold significant amounts of digital assets. The combination of high-value targets and the irreversible nature of crypto transactions has created a perfect storm for these types of attacks.


How Wrench Attacks Work

A wrench attack typically begins with criminals identifying a target someone they believe holds a significant amount of cryptocurrency. This information can be gleaned from social media, public blockchain data, or, as in the case of the recent shipping breaches, leaked customer data from hardware wallet manufacturers.

Once a target has been identified, the criminals may surveil the individual to learn their routines, the location of their crypto wallets, and any security measures they have in place. The attack itself may involve a home invasion, a kidnapping, or a physical assault designed to coerce the victim into revealing their seed phrase.

The criminals know that once they have the seed phrase, they can access the victim's crypto holdings instantly and irreversibly. The seed phrase is the master key to a crypto wallet, and anyone who possesses it can control the funds stored in that wallet.

The psychological impact of such attacks can be devastating. Victims may suffer not only financial loss but also lasting trauma from the physical and emotional violence they endured. The rise of wrench attacks represents a significant escalation in the threat landscape for crypto owners.


Trezor and SafePal's Response

Both Trezor and SafePal have warned customers to stay vigilant against phishing attacks, which rely on sending targeted messages to a person's phone number or email address in an attempt to steal their crypto. The companies have also advised customers to be cautious about unsolicited communications and to verify the legitimacy of any requests for personal information.

In a statement, Trezor emphasized that the security of its hardware wallets remains uncompromised. "The breaches were limited to the shipping partners and did not affect the security of our devices," the company said. "However, we take the privacy and security of our customers very seriously, and we are working to ensure that such breaches do not happen again."

SafePal echoed similar sentiments, urging customers to remain vigilant and to report any suspicious activity. The company also advised customers to use secure shipping options, such as requiring a signature upon delivery, to reduce the risk of interception.


The Coldcard Vulnerability

In a separate attack on a hardware wallet earlier this month, hackers stole more than $130 million in cryptocurrency directly off the blockchain by guessing the passwords set by Coinkite's Coldcard hardware wallet. The hackers, who have not yet been identified, were able to predict the seed phrases that Coldcard wallets would generate offline for their customers.

Even though the wallets and seed phrases never touched the internet, the hackers were able to generate customer wallet passwords on the fly and pluck their funds directly off the blockchain. The attack highlights a vulnerability in the random number generation process used by some hardware wallet manufacturers.

One victim said in a post on X that they had done "everything right," but that "none of it mattered… all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability."

The Coldcard attack has raised serious questions about the security of hardware wallets and the importance of rigorous testing and quality assurance. While hardware wallets are generally considered the most secure way to store cryptocurrency, the Coldcard incident demonstrates that even the best technology can have vulnerabilities.


The Broader Threat Landscape

The recent breaches and attacks highlight the broader threat landscape facing the crypto industry. As cryptocurrency has become more valuable, it has attracted the attention of increasingly sophisticated criminal networks.

In addition to physical attacks, crypto owners face threats from phishing scams, malware, and social engineering attacks. The breaches at Trezor and SafePal's shipping partners demonstrate that even companies that take security seriously can be compromised through their supply chain.

The crypto industry as a whole is working to address these threats. Hardware wallet manufacturers are continuously improving their security features, while blockchain analytics companies are developing tools to track stolen funds and identify criminals. However, the human element remains a significant vulnerability.


Protecting Yourself Against Wrench Attacks

For crypto owners, the recent breaches serve as a stark reminder of the importance of personal security. Here are some steps that can help reduce the risk of becoming a victim of a wrench attack:

  1. Limit Public Exposure: Be cautious about sharing information about your crypto holdings on social media or other public forums. The less criminals know about your wealth, the less likely you are to become a target.

  2. Use Multiple Wallets: Consider using multiple wallets to store your crypto, with only a portion of your holdings stored in a wallet that could be accessed under duress.

  3. Secure Your Home: Invest in home security measures, such as alarms, cameras, and secure locks. These can deter criminals and provide evidence in the event of an attack.

  4. Use a Secure Shipping Address: When ordering hardware wallets or other crypto-related equipment, consider using a secure shipping address, such as a post office box or a business address.

  5. Be Vigilant Against Phishing: Be cautious about unsolicited communications that ask for personal information or seed phrases. Legitimate companies will never ask for your seed phrase.

  6. Consider Multi-Signature Wallets: Multi-signature wallets require multiple signatures to authorize a transaction, making them more secure against attacks.


Industry Response and Regulation

The recent breaches have prompted calls for greater regulation of the crypto industry and stronger security standards for hardware wallet manufacturers. Lawmakers and regulators are increasingly focused on the risks posed by cryptocurrency, and the recent attacks are likely to accelerate efforts to impose stricter security requirements.

Industry groups have also called for greater collaboration between companies to share information about threats and vulnerabilities. By working together, the industry can better protect customers and reduce the risk of attacks.

The data breaches at shipping partners of Trezor and SafePal have exposed thousands of crypto owners to the risk of physical attacks and theft. The breaches highlight the vulnerability of the crypto ecosystem's supply chain and the growing threat of wrench attacks.

For crypto owners, the recent incidents serve as a reminder of the importance of personal security and the need to be vigilant against threats both online and offline. While hardware wallets remain one of the most secure ways to store cryptocurrency, they are not invulnerable, and the human element of security remains a critical factor.

As the crypto industry continues to grow and evolve, addressing these threats will be essential to maintaining trust and ensuring the long-term viability of digital assets. The recent breaches are a wake-up call for the industry and a reminder that security must be a top priority for everyone involved in the crypto ecosystem.


tech news

About the Creator

Mark Lim

Hi I am mark an automotive student and a car, tech and food enthusiast ! Im gonna try and post daily & hope you enjoy what I write and do share my page with people you know. I would gladly appreciate it! Cheers

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by Mark Lim