Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

3 weeks ago 34
Image Credits:Javier Zayas Photography / Getty Images

6:00 AM PDT · August 17, 2026

Data breaches astatine 2 shipping companies has enactment cryptocurrency owners with carnal hardware wallets astatine greater hazard of having their funds stolen, highlighting weaknesses successful the broader tech ecosystem relied connected by the crypto industry.

In caller weeks, makers of hardware crypto wallets Trezor and SafePal reported that collectively thousands of their customers had their idiosyncratic information and shipping accusation stolen during abstracted information breaches astatine their shipping partners. The crypto wallet makers provided their customers’ names, location addresses, email addresses, and telephone numbers to the shipping companies for mailing retired their hardware wallets.

The hacks did not impact the information of the wallets, a hardware instrumentality that stays offline that makes it acold much hard for hackers to compromise from implicit the internet. Instead the hackers targeted the broader proviso concatenation of tech companies to get idiosyncratic accusation astir wherever high-net worthy crypto holders live. 

By stealing the names and location addresses of hardware wallet customers, the hacks exposure crypto owners to carnal attacks that trust connected physically obtaining the effect operation stored connected the wallet by unit oregon violence. 

Known arsenic wrench attacks (referring to the usage of weapons), these kinds of real-world attacks are connected the rise arsenic criminals progressively question retired crypto belonging to high-net individuals. Blockchain information institution CertiK confirmed dozens of reported wrench attacks during 2025, up by 75% connected the erstwhile year, with robbers stealing upwards of $40 million. Crypto forensics elephantine Chainalysis puts this year’s figures at person to $30 million truthful far, with gangs utilizing kidnapping and location invasions to request a person’s crypto effect phrase.

With cognition of a person’s effect phrase, the attackers tin irreversibly instrumentality power of the person’s crypto connected the nationalist blockchain.

Both Trezor and SafePal besides warned customers to enactment vigilant against phishing attacks, which trust connected sending targeted messages to a person’s telephone fig oregon email code successful an effort to bargain their crypto.

In a abstracted onslaught connected a hardware wallet earlier this month, hackers stole much than $130 cardinal successful cryptocurrency straight disconnected the blockchain by guessing the passwords acceptable by Coinkite’s Coldcard hardware wallet. 

The hackers, who person not yet been identified, were capable to predict the effect phrases that Coldcard wallets would make offline for their customers. Even though the wallets and effect phrases ne'er touched the internet, the hackers were capable to make lawsuit wallet passwords connected the alert and pluck their funds straight disconnected of the blockchain.

One unfortunate said in a station connected X that they had done “everything right,” but that “none of it mattered… each due to the fact that the hardware that created the effect operation primitively had 1 enactment successful their codification from 2021 that had a vulnerability.”

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.

Read Entire Article