Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
web3: Higher Security Risks Faced After Hardware Wallet User Data Leak

web3: Higher Security Risks Faced After Hardware Wallet User Data Leak

币界网币界网2026/08/17 15:47
Show original

After recent consecutive data leaks at two logistics companies, users holding crypto hardware wallets are facing new security pressures. Trezor and SafePal have both stated that the personal and shipping information of thousands of customers was stolen from their respective logistics partners. According to foreign media, the incidents have not directly affected the offline storage function of the wallets, but have exposed the crypto industry's dependence risk on external supply chains.

Leaked information reveals real addresses

The two companies provided the logistics partners with names, home addresses, email addresses, and phone numbers as required for shipment. Once this information falls into the hands of attackers, the risks go far beyond spam emails or scam calls.

The bigger issue is that attackers can use this data to identify which addresses may correspond to users holding significant crypto assets, potentially launching targeted phishing attacks or even shifting from online attacks to in-person threats.

Rising risk of offline violent mnemonic phrase theft

Reports mention that although the hardware wallets themselves were not remotely breached, users may now be exposed to so-called "wrench attacks." Such incidents typically involve kidnapping, home invasion, or violent threats to force victims to hand over their mnemonic phrases, thereby transferring on-chain assets.

Blockchain security firm CertiK stated that dozens of such cases have already been confirmed in 2025, marking a 75% increase from the previous year, with losses exceeding $40 million. Chainalysis reports that losses so far this year are close to $30 million, with some groups employing kidnapping and home invasion tactics to obtain mnemonic phrases.

Once attackers obtain a mnemonic phrase, they can directly control the corresponding crypto assets in the wallet, and on-chain transfers are typically irreversible.

New incidents involving hardware wallets themselves

In addition to supply chain leaks, there have also been recent security incidents involving the hardware wallets themselves. Reports noted that earlier this month, attackers were able to guess passwords for Coldcard hardware wallets from Coinkite, directly stealing over $130 million in crypto assets from the blockchain.

The reports indicate attackers could predict certain mnemonic phrases generated offline by Coldcard wallets. Even if the wallet and mnemonic phrase never touched the internet, attackers could dynamically generate customers' wallet passwords and directly transfer funds on-chain.

Trezor and SafePal also remind users to beware of phishing attacks, including targeted messages sent via SMS, phone, or email. For hardware wallet users, risks now come not only from the devices themselves but also from peripheral processes such as logistics, data handling, and after-sales communication.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!