Data breaches at shipping partners have exposed personal information linked to some cryptocurrency hardware wallet customers, raising concerns about phishing and physical security.
Recent incidents involving shipping providers connected to Trezor and SafePal exposed customer information such as names, addresses, email addresses and phone numbers.
The hardware wallets themselves were not directly compromised in these breaches. However, the leaked information could make affected crypto users easier targets for criminals.
Why Hardware Wallet Users Are at Risk
Hardware wallets are designed to keep cryptocurrency keys offline, making them harder to attack remotely.
But protecting the wallet itself is only one part of crypto security.

When customers order a physical wallet, companies may need to share delivery information with shipping providers. If that information is stolen, attackers could potentially learn where crypto hardware wallet owners live.
This creates a different type of security risk that happens outside the wallet’s technology.
Phishing Is Another Concern
Trezor and SafePal have also warned customers to be careful about targeted phishing attempts.
Attackers with access to a customer’s name, phone number or email address could create convincing messages pretending to be a wallet company or another trusted service.
Users should avoid clicking unexpected links, sharing recovery phrases or entering wallet credentials into websites received through unsolicited messages.
Hardware Security Can Still Have Software Risks
The recent incidents also highlight that offline hardware is not automatically immune to security problems.
Earlier this month, a separate vulnerability involving Coldcard hardware wallets reportedly resulted in more than $130 million in cryptocurrency being stolen.
The incident showed how a flaw in the process used to generate wallet seed phrases could potentially put funds at risk, even when the wallet itself was designed to operate offline.
What Crypto Users Should Do
Crypto owners can reduce their exposure by taking a few basic precautions:
- Keep recovery or seed phrases private and offline.
- Never share a seed phrase through email, messages or websites.
- Be suspicious of unexpected wallet-related messages.
- Avoid revealing unnecessary information about cryptocurrency holdings.
- Keep hardware wallet software and security guidance up to date.
- Consider the privacy risks of using a home address when ordering crypto hardware.
Read More on VitalStack
Enjoyed this article?
Subscribe for weekly deep-dives on AI and health — straight to your inbox.