Trezor, SafePal Users Exposed in Shipping Partner Hacks

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Trezor and SafePal disclosed that thousands of customers had their names, home addresses, email addresses, and phone numbers stolen in separate data breaches at the shipping companies handling hardware wallet deliveries.
- The attacks did not compromise the wallet devices themselves but instead targeted shipping partners to map the locations of high-net-worth crypto holders.
- CertiK confirmed dozens of "wrench attacks" in 2025, up 75% year-over-year, with criminals stealing upwards of $40 million; Chainalysis puts the figure closer to $30 million.
- With a victim's seed phrase, attackers can irreversibly drain crypto holdings from the public blockchain; both wallet makers also warned customers about targeted phishing attempts using the stolen contact details.
- In a separate attack, Coinkite's Coldcard wallets lost more than $130 million when hackers predicted offline-generated seed phrases by exploiting a 2021 code vulnerability.
Why it matters: Crypto hardware wallet owners — historically protected by keeping private keys offline — now face physical danger because the supply chain around those wallets leaks their home addresses. With wrench attacks up 75% year-over-year and $30–40 million already stolen in 2025, even offline cold storage cannot shield owners from being targeted in their homes.
Ask SkimNews



