Data of 13,689 Trezor customers was leaked after an unauthorized access to ShipMonk, one of the company’s current shipping providers. Trezor concluded that internal systems, wallets, and other devices had not been compromised, but acknowledged that scammers might target owners of its wallets for phishing attacks using the shipping records. The breach exposed names, email addresses, phone numbers, and shipping addresses for 11,742 customers, while another 1,947 customers had their names, cities, and email addresses stolen. Trezor stated that “the breach is limited due to Trezor’s strict 90-day data storage policy.”
ShipMonk informed Trezor of the incident on August 10, after which Trezor released a public statement about the breach on August 13. The investigation is still ongoing.
The affected orders were delivered in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal from May 10 to August 8. Trezor stated that the breach did not extend to user wallet backups, private keys, or payment data, and noted no interruption to its service or products.
The risk comes from criminals knowing who owns a hardware wallet and, in some cases, where that person lives. With this information, they could pretend to be from Trezor, a cryptocurrency exchange, or financial institution via email, phone, or correspondence.
This incident follows the recent Coldcard exploit, although the two cases are different. Coldcard suffered from a flaw that caused wallet seeds on certain devices to be created incorrectly. According to TRM Labs, by August 5, 1,816 BTC, which is around $116 million, had been stolen by attackers.
The Trezor breach did not expose wallet keys or directly compromise customer funds. It was a security failure at a third-party shipping provider that exposed customer identities, leaving phishing and impersonation as the most obvious dangers. Trezor says affected customers have been contacted, and users have been warned to distrust unsolicited communications.
