Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Trezor and SafePal disclosed that separate data breaches at their shipping partners exposed thousands of customers' names, home addresses, email addresses, and phone numbers — information the wallet makers had shared for delivery
- The breaches did not compromise the hardware wallets themselves, which stay offline; instead the attackers targeted the broader tech supply chain to identify where high-net-worth crypto holders live
- CertiK documented dozens of wrench attacks during 2025, a 75% year-over-year increase, with criminals stealing more than $40 million by forcing victims to surrender their seed phrases
- Chainalysis pegged 2025 losses closer to $30 million, noting that gangs are increasingly using kidnapping and home invasions to extract seed phrases
- Once an attacker obtains a seed phrase, they can irreversibly seize the victim's crypto directly from the public blockchain
- Trezor and SafePal also warned customers to stay vigilant against phishing attacks leveraging the stolen phone numbers and email addresses
Why it matters: Thousands of high-net-worth crypto holders now have their home addresses in criminal hands, turning physical security into the weakest link in an otherwise offline custody setup. With wrench attacks up 75% in 2025 and $30–40 million already stolen through physical coercion, the threat vector has shifted from digital to bodily — even a perfectly secured hardware wallet cannot protect against a knife.
Ask SkimNews



