“`html
Cryptocurrency hardware wallet users are facing heightened vulnerability to physical attacks following data breaches at shipping companies that distribute these security devices. Popular wallet makers Trezor and SafePal recently disclosed that thousands of customers had their personal information compromised, including names, addresses, and contact details that had been shared with logistics partners for device delivery.
The breaches create a concerning security gap in an otherwise robust ecosystem. While the hardware wallets themselves remained secure, the stolen customer data provides criminals with the residential locations of potentially wealthy cryptocurrency holders. This information facilitates so-called wrench attacks, in which criminals use violence or threats to coerce victims into revealing their wallet seed phrases—the cryptographic keys that grant complete control over digital assets. Security firms have documented a sharp rise in such attacks, with incidents increasing 75% year-over-year and losses climbing into the tens of millions of dollars annually.
The shipping company hacks also underscore broader vulnerabilities extending beyond supply chain compromises. A separate incident involving Coinkite’s Coldcard wallet resulted in thieves stealing over $130 million by successfully predicting seed phrases generated offline. The attack exploited a coding flaw from 2021, demonstrating that even offline security measures cannot guarantee complete protection against sophisticated threats.
Both Trezor and SafePal have advised customers to remain alert for phishing attempts targeting their phone numbers and email addresses. The incidents highlight the complex security landscape facing cryptocurrency holders, where even hardware-based protections require vigilance across multiple threat vectors.
“`
