Technology

Shipping Vendor Breaches Expose Hardware Wallet Customers to Phishing and Physical Attacks

Martin HollowayPublished 2w ago6 min readBased on 14 sources
Reading level
Shipping Vendor Breaches Expose Hardware Wallet Customers to Phishing and Physical Attacks
Photo by Tiger Lily on Pexels

Two third-party shipping companies have been breached, exposing the personal information of thousands of hardware cryptocurrency wallet customers and putting them at heightened risk of both phishing scams and physical attacks aimed at stealing their seed phrases.

Trezor disclosed on August 13, 2026 that nearly 14,000 of its customers had their names, home addresses, email addresses, and phone numbers exposed in a breach at ShipMonk, its third-party fulfillment partner. SafePal reported a separate but similar breach at one of its own shipping partners. The wallet makers had handed customer details to these logistics companies so they could mail physical hardware devices. Neither breach compromised the hardware wallets themselves or the cryptographic material stored on them. The attack surface was the supply chain, not the secure element — the tamper-resistant chip inside the device that holds private keys.

The distinction matters but offers limited comfort. The wallets are fine; the people who own them are now identifiable targets.

By combining stolen names and home addresses with the knowledge that these individuals bought hardware wallets, attackers now have a curated list of likely high-net-worth crypto holders and where they live. That combination enables what the industry calls wrench attacks — named for the cartoonish extremity of physically coercing someone into surrendering their seed phrase. Blockchain security firm CertiK confirmed dozens of reported wrench attacks during 2025, a 75% increase over the previous year, with losses exceeding $40 million. Crypto forensics company Chainalysis placed 2026 wrench-attack losses at approximately $30 million so far, with attackers resorting to kidnapping and home invasions to demand victims' seed phrases directly.

Once an attacker obtains a seed phrase, the outcome is irreversible. The phrase grants full control of the associated wallet on the public blockchain, and transactions cannot be reversed, insured through conventional banking mechanisms, or recovered without the recipient's cooperation. A seed phrase is a series of words generated by the wallet that serves as a master key — anyone who has it can access and move all funds tied to that wallet.

Trezor and SafePal both warned customers to remain vigilant against phishing, the more scalable threat. With email addresses and phone numbers in hand, attackers can craft targeted messages impersonating the wallet makers, urging recipients to enter their seed phrase on a fake recovery page. This is a well-established attack pattern in the crypto space. In April 2018, MyEtherWallet suffered a DNS hijack that redirected users to a malicious server, resulting in losses for those who interacted with the fraudulent site.

The shipping breaches are not the only security event hitting the hardware wallet ecosystem this month. In a separate attack earlier in August 2026, hackers stole more than $130 million in cryptocurrency from holders of Coinkite's Coldcard hardware wallets by exploiting a bug that allowed them to predict the seed phrases the devices generated offline. The wallets and their seed phrases never touched the internet. The Financial Times reported that more than $100 million was stolen from Coldcard holders on July 30 after the bug led to private keys not being generated correctly. Bloomberg Crypto aired a segment titled "Bitcoin Wallet Hack Shakes Industry" on August 11, 2026.

The Coldcard incident is a category apart from the shipping breaches. One is a cryptographic implementation failure that defeated the core security promise of an offline device. The other is a conventional data breach at a logistics vendor that nonetheless produces a physical threat most crypto holders never planned for.

Looking at what this means for the hardware wallet model, the supply-chain exposure reveals a structural tension. The security architecture of a hardware wallet assumes the device itself is the trust boundary: keys are generated and stored offline, transactions are signed on-device, and the seed phrase never leaves the owner's physical control. But the business of selling and shipping those devices requires entrusting a name, address, email, and phone number to a fulfillment company whose security the wallet maker does not control and whose customer base extends far beyond crypto. The hardware is air-gapped — cut off from the internet by design. The customer database is not.

This is not unique to crypto, of course. Anyone who has ever ordered a high-value item to their home address has created a similar, if lower-stakes, data trail. But the combination of a known crypto affiliation and a physical address creates a targeting dataset that a generic retail shipping record does not.

The broader context here is that the aggregate loss figures for crypto crime in 2025 give a sense of the stakes. Cybercriminals stole $2.7 billion in crypto in 2025, with an additional $700,000 tracked as stolen from individual crypto wallets, according to data cited by TechCrunch. In June 2025, hackers stole at least $90 million from Iran's largest crypto exchange across multiple transactions, per blockchain analysis firm Elliptic. And in July 2026, an AI agent carried out the technical execution of a real-world ransomware attack for the first known time, though a human was still required for parts of the operation. The threat landscape spans protocol-level exploits, exchange compromises, AI-assisted attacks, and now supply-chain-enabled physical coercion.

The wallet makers' guidance to customers is straightforward: be alert to phishing, do not share seed phrases, and treat any unsolicited communication as suspicious. That is necessary but, given the home-address exposure, not sufficient to address the physical risk. Customers whose data was exposed in the ShipMonk breach face a threat that customer-side vigilance alone cannot fully mitigate. In my view, the industry will need to reckon with the fact that the most cryptographically secure device in the world still depends on a shipping label with a name and address on it — and that label is only as secure as the logistics company holding it.