Key Highlights
- Trezor exposed data of another 67,000 US customers in a shipping provider breach.
- The exposed details include names, email addresses, phone numbers and shipping addresses.
- Trezor said its systems, devices, wallet backups and private keys were not compromised.
Trezor, the crypto firm that invented the world’s first hardware wallet, revealed that the data breach at one of its shipping providers affected another 67,000 customers in the US, adding to the thousands of people already known to be caught in the incident.
The customers placed orders between November 2019 and August 2021, and their personal details were exposed through the breach.
Trezor in a post on X on Friday, said these newly affected customers had their names, email addresses, phone numbers and shipping addresses exposed. The company said it has contacted all customers included in the latest disclosure and warned them to be careful about messages or calls that appear to come from Trezor.
Customers’ personal details were exposed
This figure is a big jump compared to the 13,689 customers Trezor first reported in August. The earlier disclosure involved customers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who received Trezor orders between May 10 and August 8.
The breach happened at ShipMonk, a third-party company that handled shipping services for Trezor. ShipMonk informed Trezor about unauthorized access on August 10, after which an investigation began into what information had been accessed.
Trezor devices and wallets remain secure
Trezor said the breach did not affect its own systems or devices. The company also said no wallet backup or private key was exposed. This means the information taken in the incident does not give someone access to a customer’s cryptocurrency stored on a Trezor device.
“Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security.
NEVER share your wallet backup with anyone or type it into a website,” the Prague-based company said.
Customers warned about scams and physical risks
The earlier investigation found that 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had only partial information exposed, including their name, city and email address.
Trezor had previously explained that its shipping partners keep order information for only 90 days. Older records had already been deleted or made anonymous, which limited the amount of customer data available from older orders.
Crypto attacks on holders continue to rise
With the latest disclosure, however, the incident has grown far beyond the original number of affected customers. Trezor is now warning customers to watch out for fake emails, phone calls and letters. It also pointed to possible physical-security concerns because some exposed records contain home or delivery addresses.
The warning is important for crypto users because leaked personal details can be used for more than online scams. Criminals can use names, phone numbers and addresses to identify people who may own cryptocurrency.
The incident comes as physical attacks against crypto holders are increasing. These attacks include home invasions, kidnappings and hostage situations, often called “wrench attacks.”
Blockchain analytics firm Chainalysis said criminals have stolen more than $30 million from crypto holders through such attacks in 2026. That figure puts the year on track to pass the $58 million stolen through similar attacks in 2025.
Also Read: Polymarket Launches Perps With Up to 20x Leverage for Global Traders
