Trezor Shipping Partner Breach Exposes 80,000+ Hardware Wallet Customers
Trezor, a maker of hardware cryptocurrency wallets, has disclosed that a breach at its shipping provider ShipMonk affected roughly 80,689 US customers in total, including an additional 67,000 people identified in a Sept. 4 update covering orders placed between 2019 and 2021. ShipMonk had previously told Trezor in writing that it had deleted these records, but the update shows that assurance did not hold up.
Trezor says the exposed information was limited to names and delivery addresses, and that no wallet contents, private keys, or funds were affected. The devices themselves remain secure because hardware wallets are designed so that private keys never leave the device, meaning a breach of a retailer or shipper does not directly put customer funds at risk.
The real danger from this kind of leak is not theft of cryptocurrency but the potential for scammers to use the exposed contact details to impersonate trusted companies or couriers, targeting known crypto wallet owners with phishing or social engineering attempts. Because recovery phrases, not shipping data, are what protect access to funds, customers are reminded never to share or digitally store their wallet backup phrases.