
Hardware Wallets Are Air-Gapped. Their Shipping Records Are Not.
Breaches at shipping partners for Trezor and SafePal exposed personal data — names, addresses, emails, phone numbers — of about 14,000 Trezor customers plus an undisclosed number of SafePal users. The wallets themselves were not compromised. The structural issue: buying an air-gapped device creates a physical-address trail linking buyers to likely crypto holdings — a target list for coercion-based attacks, which CertiK says rose 75% in 2025, exceeding $40 million in losses.
Published