Trezor Data Breach: 67,000 Users Exposed via ShipMonk
Trezor confirms a data breach via third-party provider ShipMonk, exposing addresses and phone numbers of 67,000 customers from 2019 to 2021.
Users who placed orders between November 2019 and August 2021 have been affected, though Trezor emphasized that its own infrastructure and customer devices remain uncompromised.
Leaked Data Includes Addresses and Phone Numbers
The newly identified records contain names, email addresses, phone numbers, shipping addresses, and order numbers. This information originated from the order fulfillment and shipping process in the U.S., where Trezor utilized services provided by ShipMonk.
According to the company, the breach does not include seed phrases, private keys, or any other information required to directly access crypto assets within hardware wallets. This creates a critical distinction between a personal data compromise and a breach of the cryptocurrency storage system itself.
However, the risks remain significant. The combination of a name, email, phone number, and physical address allows scammers to build much more convincing phishing campaigns specifically targeting individuals known to have purchased a hardware wallet.
ShipMonk Assured Trezor That Data Was Deleted
A more serious corporate concern involves how this data remained on ShipMonk’s systems. Trezor reported that the provider had repeatedly confirmed the information was deleted, yet a subsequent audit revealed it was still being stored.
This indicates the issue extends beyond the initial security incident. When working with external vendors, deleting customer records after the necessary retention period expires is vital to limiting the amount of information exposed during a future breach.
In this instance, order data from several years ago remained accessible despite assurances to the contrary. This prolonged storage allowed older customer records to fall within the expanded scope of the incident.
Customer Hardware Wallets Remain Secure
Trezor stated that its internal systems were not compromised. There are no indications that the incident affected the devices themselves or the cryptographic mechanisms users rely on to protect their private keys.
This technical distinction is crucial. A hardware wallet keeps keys isolated from e-commerce and shipping systems, whereas ShipMonk handles the data necessary for physical product delivery. Consequently, a breach in one infrastructure does not grant automatic access to the other.
The most immediate threat is social engineering. For example, a Trezor owner might receive a message using their real name or old order details, claiming the device needs an update or the wallet must be recovered. If such communication requests a seed phrase or private key, providing them would lead to the theft of funds, regardless of the hardware’s inherent security.
Expanded Breach Increases Risk of Targeted Scams
The addition of 67,000 affected customers makes third-party data management the central issue following the incident. For companies selling self-custody products, physical addresses are more sensitive than standard e-commerce data because they identify households likely to hold cryptocurrency.
The exposure of order numbers also enhances the credibility of future scams. An attacker does not need access to the wallet if they can convince the owner to voluntarily hand over recovery information.
Future focus will likely shift toward the full extent of data remaining at ShipMonk and whether the currently identified records represent the final count of affected customers. For Trezor, the case raises questions regarding the lifecycle control of information shared with external partners, particularly when deletion has already been confirmed.

Fill in necessary fields and publish