Key Highlights
- 13,689 Trezor customers were affected by unauthorized access at third-party shipping provider ShipMonk.
- 11,742 customers had full contact and shipping details exposed, while 1,947 had partial information disclosed.
- Wallet recovery phrases and private keys were not exposed, with Trezor saying its own systems and products were not breached.
Trezor, a crypto hardware wallet brand, has disclosed a data breach at its third-party shipping provider ShipMonk that exposed personal information belonging to 13,689 customers.
According to a Trezor blog post on Thursday, the exposed information includes customer names, email addresses, phone numbers, and shipping addresses. The company said ShipMonk notified it of unauthorized access on August 10 and that an investigation is still underway.
The affected customers received Trezor orders from the U.S., U.K., Sweden, Colombia, Brazil, Italy, or Portugal between May 10 and August 8.
13,689 customers affected
Trezor said 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had partial information exposed, consisting of their name, city and email address.
The company attributed the limited scope of the incident to a 90-day data-retention requirement for order information held by its fulfillment partners. Older records had already been deleted or anonymized, according to Trezor.
Trezor said affected customers were notified separately by email.
Breach could increase phishing risk
The exposed information does not include wallet recovery phrases or private keys, but it could give scammers information about people who own Trezor hardware wallets. That creates a potential avenue for more targeted phishing and impersonation attempts.
Attackers with a customer’s name, phone number, and shipping address could potentially pose as Trezor, a crypto exchange or another financial service and make fraudulent messages appear legitimate.
Trezor said, “The affected customers might be targeted by more sophisticated phishing attempts.” The company advised users not to provide wallet backups or other sensitive credentials in response to unsolicited communications.
Trezor says its systems were not breached
According to the company, the incident was limited to ShipMonk’s systems. Trezor said its own infrastructure, products, and services were not compromised. The company is working with ShipMonk to determine how the unauthorized access occurred and what customer information was accessed.
The distinction is important for affected users: the disclosed incident concerns customer data held by a logistics provider, rather than direct access to Trezor wallets or their cryptographic keys.
Recent phishing incident targeted Trezor users
The breach comes days after Trezor warned users about a separate phishing campaign.
On August 8, the company reported that a fake Trezor website had appeared in Google search results and was asking users to provide wallet backups. The incident reportedly affected around 80 victims.
That incident did not involve a breach of Trezor’s customer database and is separate from the ShipMonk incident.
However, the timing highlights a broader problem for hardware-wallet users: personal information, search-engine manipulation, and fake websites can all be used together in attempts to obtain wallet credentials.
Separate Safe 7 chip issue disclosed in June
Trezor also disclosed a separate security issue in June involving the TROPIC01 chip used in its Safe 7 hardware wallet. The issue was identified during an independent assessment and involved the device’s secure element rather than customer information.
Trezor said exploiting the issue would require physical access to the device and specialized equipment, and said it did not provide direct access to users’ wallet backups or funds. The chip disclosure is unrelated to the ShipMonk breach.
Third-party data adds another security risk
The ShipMonk incident shows another layer of risk surrounding crypto self-custody.
While wallet security typically focuses on private keys, recovery phrases, and device protection, hardware-wallet purchases also generate personal information that is stored by companies involved in fulfillment and delivery.
In this case, the compromised information could potentially be used to identify Trezor customers and target them with personalized scams.
Trezor said its investigation with ShipMonk is ongoing. The company has contacted customers it identified as affected, while the full circumstances of the unauthorized access have yet to be established.
Also Read: Solana Stays Online Despite 102 of 699 Validators Going Offline
