This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$63,478+0.76%ETH$1,898+0.96%SOL$75.3+0.11%XRP$0.9971-0.21%DOGE$0.0699+0.14%ADA$0.1733-1.61%Total Cap$2.28T+0.58%Layer Index44 Neutral
External ReportingYayınlandı 7 dakika önce

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

Data breaches at two shipping companies has put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry.

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
Publisher TechCrunch 2 dk okuma
NewsLayer editorial artwork

Regulation Context

SEC Crypto Asset Market Structure Rulemaking
JurisdictionUnited States
RegulatorSEC
Statusin progress
Updated10 gün önce

Layer Index

44

↑ 2 pts in 24h

Data breaches at two shipping companies has put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry.

In recent weeks, makers of hardware crypto wallets Trezor and SafePal reported that collectively thousands of their customers had their personal data and shipping information stolen during separate data breaches at their shipping partners. The crypto wallet makers provided their customers’ names, home addresses, email addresses, and phone numbers to the shipping companies for mailing out their hardware wallets.

The hacks did not affect the security of the wallets, a hardware device that stays offline that makes it far more difficult for hackers to compromise from over the internet. Instead the hackers targeted the broader supply chain of tech companies to obtain personal information about where high-net worth crypto holders live. 

By stealing the names and home addresses of hardware wallet customers, the hacks expose crypto owners to physical attacks that rely on physically obtaining the seed phrase stored on the wallet by force or violence. 

Known as wrench attacks (referring to the use of weapons), these kinds of real-world attacks are on the rise as criminals increasingly seek out crypto belonging to high-net individuals. Blockchain security company CertiK confirmed dozens of reported wrench attacks during 2025, up by 75% on the previous year, with robbers stealing upwards of $40 million. Crypto forensics giant Chainalysis puts this year’s figures at closer to $30 million so far, with gangs using kidnapping and home invasions to demand a person’s crypto seed phrase.

With knowledge of a person’s seed phrase, the attackers can irreversibly take control of the person’s crypto on the public blockchain.

Both Trezor and SafePal also warned customers to stay vigilant against phishing attacks, which rely on sending targeted messages to a person’s phone number or email address in an attempt to steal their crypto.

In a separate attack on a hardware wallet earlier this month, hackers stole more than $130 million in cryptocurrency directly off the blockchain by guessing the passwords set by Coinkite’s Coldcard hardware wallet. 

The hackers, who have not yet been identified, were able to predict the seed phrases that Coldcard wallets would generate offline for their customers. Even though the wallets and seed phrases never touched the internet, the hackers were able to generate customer wallet passwords on the fly and pluck their funds directly off of the blockchain.

One victim said in a post on X that they had done “everything right,” but that “none of it mattered… all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

Son Dakika

Hiçbir son dakika haberini kaçırmayın

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by TechCrunch

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

İlgili Haberler