Following the recent data leaks by two logistics companies, users with encryption hardware wallets faced new security pressures. Térezor and SafePal have stated, after all, that the personal and receipt information of thousands of clients has been stolen from their logistics partners. According to external sources, the incident did not directly affect offline storage of wallets, but exposed the risk of the encryption industry relying on external supply chains.
The leak leads to the real address.
The two companies provided logistics operators with the required names, home addresses, mailboxes and telephone numbers for the mail. Once such information falls into the hands of the attackers, the risk is not limited to spam or fraudulent telephone calls.
The larger problem is that the attackers can identify, on this basis, the locations that may be used by users who should have more encrypted assets, and further launch targeted fishing, or shift on-line attacks to lower-line threats.
The risk of sub-linear violence demanding assistive notes has increased.
It was mentioned that the hardware wallet itself had not been breached remotely, but that the user might have been exposed to the so-called “thrower attack”. Such cases often result in the transfer of assets from the chain by forcing victims to hand over their notes through kidnapping, burglaries or threats of violence.
CertiK stated that dozens of related cases had been identified in 2025, an increase of 75 per cent over the previous year, with more than $40 million stolen. The statistics given by Chainalysis so far this year are close to US$ 30 million, and some of the groups have used kidnapping and entry methods to obtain assistive notes.
Once the attackers have access to assistive notes, they have direct control of the encoded assets in the corresponding wallets, and chain transfers are usually not withdrawn.
There are new cases in the hardware wallet itself.
In addition to leaks in the supply chain, new security incidents have occurred recently in the hardware wallet itself. The report mentions that earlier this month, the attackers directly stole more than $130 million of encrypted assets from the chain by speculating on the code of the Coinkite hardware wallet of Coldcard.
According to the report, the attackers were able to predict the de-linking of part of the Coldcard wallet. Even if the wallet and assistive words never come into contact with the Internet, the assailant can still generate the client's wallet passwords and transfer the money directly from the chain.
Térezor and SafePal also alert users to fishing attacks, including targeted messages via text messages, telephones or e-mails. For users of hardware wallets, the risk has come not only from the equipment itself but also from the peripherals of logistics, data processing and after-sales connections.
