Shipping Partner Breaches Expose Trezor and SafePal Users to Wrench Attacks
Trezor and SafePal shipping breaches exposed thousands of wallet owners to phishing and violence, while a Coldcard flaw enabled a $130 million crypto theft.
Summary
Separate breaches at shipping partners used by Trezor and SafePal exposed the names, home addresses, email addresses and phone numbers of thousands of hardware wallet customers, the companies reported before August 17, 2026. The wallets were not compromised, but the stolen data can support targeted phishing and wrench attacks, including kidnappings and home invasions intended to force disclosure of seed phrases and irreversibly seize cryptocurrency on public blockchains. Both companies urged customers to remain vigilant.
CertiK confirmed dozens of wrench attacks in 2025, 75% more than the previous year, with losses exceeding $40 million. Chainalysis estimates gangs have stolen closer to $30 million so far this year. In a separate attack earlier in August 2026, unidentified hackers stole more than $130 million by exploiting a vulnerable line of 2021 code in Coinkite’s Coldcard hardware wallet, predicting seed phrases generated offline and producing customer wallet passwords without the wallets or phrases reaching the internet. One victim wrote on X that following security precautions proved futile because the original hardware generated a vulnerable seed phrase.
Positives
- Trezor and SafePal said their hardware wallets remained uncompromised during the shipping partner breaches.
- Offline storage prevented the exposed Trezor and SafePal devices from being directly breached over the internet.
- Trezor and SafePal warned affected customers to watch for targeted phishing through their exposed phone numbers and email addresses.
- CertiK and Chainalysis have documented wrench attack losses, providing concrete measures of the escalating physical threat.
Risks & concerns
- Thousands of Trezor and SafePal customers had names, home addresses, email addresses and phone numbers stolen from shipping partners.
- CertiK recorded dozens of wrench attacks in 2025, up 75%, with criminals stealing more than $40 million.
- Chainalysis estimates kidnappings and home invasions have enabled nearly $30 million in cryptocurrency theft so far this year.
- A 2021 Coldcard code vulnerability let unidentified hackers predict offline seed phrases and steal more than $130 million.
- Seed phrase disclosure gives attackers irreversible control of a victim’s cryptocurrency on public blockchains.