IT-PUB NEWS

Trezor and SafePal breaches expose customer data

18.08.2026 12:03 • Author: IT-PUB
Trezor and SafePal breaches expose customer data

Data stolen from shipping partners included names, addresses, emails, and phone numbers, creating new phishing and physical risks for hardware wallet buyers.

Crypto hardware wallet users are dealing with a different kind of security threat after breaches at two shipping companies exposed customer details tied to Trezor and SafePal orders. The incidents did not compromise the wallets themselves, but they did reveal personal data that can make owners easier targets for scams and even physical attacks. That is what makes this case notable: the weak point was not the device, but the logistics chain around it.

For people who use hardware wallets to keep crypto offline, that distinction matters. A secure device can still leave its owner exposed if shipping records and contact details fall into the wrong hands.

Shipping breaches exposed customer contact details

In recent weeks, Trezor and SafePal said that thousands of customers had personal data stolen in separate breaches involving their shipping partners. The information shared with delivery companies included names, home addresses, email addresses, and phone numbers used to send hardware wallets.

Both companies said the wallets themselves were not compromised. Hardware wallets are built to stay offline, making them much harder to attack over the internet than software wallets or exchange accounts.

The stolen shipping data still carries real weight. For crypto owners, a home address linked to a wallet purchase may be enough to identify someone who could hold significant assets, as IT-PUB News reports.

Why the leak creates a real-world security risk

The central concern is not online theft through the wallet device. It is the risk of physical crime aimed at forcing people to reveal their seed phrase — the recovery key that gives full control over crypto funds on the blockchain.

The source describes these crimes as “wrench attacks,” a term used for assaults or threats involving force or weapons. In these cases, attackers try to get the seed phrase through intimidation, kidnapping, or home invasion rather than by hacking the wallet online.

Once an attacker gets the seed phrase, the funds can be taken irreversibly on the public blockchain. There is no central bank or support desk that can simply undo the transfer.

Wrench attacks are rising in 2025

The shipping breaches drew extra attention because they come at a time when physical attacks on crypto holders are already increasing. Security company CertiK said it confirmed dozens of reported wrench attacks during 2025, up 75% from the previous year. CertiK said robbers stole upwards of $40 million.

Chainalysis gave a lower estimate for this year so far, putting the total closer to $30 million. It said gangs have used kidnapping and home invasions to pressure victims into handing over their crypto seed phrases.

The totals differ, but the direction is the same. Criminals are increasingly treating crypto owners as physical targets, not just online ones.

Trezor and SafePal also warned about phishing

Alongside the breach warnings, both Trezor and SafePal told customers to watch for phishing attempts. These attacks usually rely on targeted messages sent by email or phone in an effort to trick people into giving up crypto credentials or other sensitive information.

That makes the stolen contact data especially useful to attackers. A name, address, email, and phone number can help criminals craft messages that look legitimate and are harder to dismiss.

For users, the risk goes beyond a single stolen database. Once personal details are exposed, they can be reused in repeated scams aimed at the same people.

Another hardware wallet attack raised fresh doubts

The shipping breaches were not the only recent incident to rattle confidence in hardware wallet security. Earlier this month, hackers stole more than $130 million in cryptocurrency from Coinkite’s Coldcard hardware wallet by guessing the passwords set by the device.

According to the source, the attackers were able to predict the seed phrases that Coldcard wallets would generate offline for customers. Even though the wallets and seed phrases never touched the internet, the hackers were still able to generate wallet passwords and move funds directly from the blockchain.

One victim said in a post on X that they had done “everything right,” but that “none of it mattered… all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

That reaction helps explain why these incidents have drawn so much attention. Hardware wallets are often treated as one of the safest ways to store crypto, yet recent cases show how that safety can still be undermined by weaknesses in surrounding systems, whether in shipping logistics or device code.

The broader lesson for crypto users

Taken together, the incidents point to a weak spot in the broader ecosystem around crypto storage. Even when a wallet stays offline, the person buying it can still be exposed through shipping records, contact details, and other operational data.

For crypto owners, security is not just about the device in hand. It also depends on how personal data is handled before the product arrives, and on how much of that information can be tied back to a home address.

The cases involving Trezor, SafePal, and Coldcard also show how far the threat model has expanded. Criminals are not only trying to break into wallets over the internet. They are also looking for ways to identify owners, pressure them in person, or exploit weaknesses in the tools meant to protect them.


Improve SEO for a small/medium business website for $50