Thousands of cryptocurrency hardware wallet customers are at greater risk of having their funds stolen following data breaches at two shipping companies. Makers of hardware crypto wallets, Trezor and SafePal, reported that their customers' personal data and shipping information were stolen during separate incidents at their shipping partners.
The stolen information includes customers' names, home addresses, email addresses, and phone numbers. This data theft exposes crypto owners to physical attacks, known as "wrench attacks," which involve obtaining a wallet's seed phrase by force. Blockchain security company CertiK confirmed dozens of such attacks in 2025, with robbers reportedly stealing over $40 million.
Crypto forensics firm Chainalysis estimates that approximately $30 million has been stolen this year through methods like kidnapping and home invasions to demand seed phrases. Trezor and SafePal have also advised customers to be vigilant against phishing attacks targeting their phone numbers or email addresses.
In a separate incident earlier this month, hackers reportedly stole more than $130 million in cryptocurrency from Coinkite's Coldcard hardware wallets. The attackers were able to predict the seed phrases generated offline by these wallets, allowing them to access funds directly from the blockchain.