Recent data breaches involving shipping partners have placed some hardware wallet users under renewed scrutiny, as personal details tied to crypto deliveries were exposed. The incidents affected customers of Trezor and SafePal, whose names, home addresses, email addresses, and phone numbers were shared with logistics providers for shipment purposes.
Importantly, the wallets themselves were not compromised. Hardware wallets remain offline by design, which makes them far harder to attack remotely. The new risk emerged elsewhere in the ecosystem: attackers gained access to customer identity and delivery data, information that can be used to identify high-value crypto holders.
Security experts note that this kind of exposure can increase the chance of targeted social engineering and so-called wrench attacks, where criminals try to obtain a victim's seed phrase through coercion or intimidation. Blockchain security firm CertiK has reported a sharp rise in such cases during 2025, while Chainalysis also points to a growing number of violent crypto-related theft attempts.
Both wallet makers have advised users to stay alert for phishing messages sent through email or phone, especially when those messages appear personalized. In a separate incident earlier this month, Coinkite's Coldcard wallet was also linked to a major blockchain theft after attackers exploited a weakness in offline seed generation.
The episode underscores a larger lesson for the crypto industry: security is no longer only about code, but also about the entire chain of custody around digital assets. As the sector matures, stronger privacy controls and supply-chain safeguards may become just as important as wallet encryption itself.