Full story
Breach widens via ShipMonk
Trezor said a data breach at its shipping partner ShipMonk exposed personal information for another 67,000 U.S. customers, pushing the known total number of affected users to 80,700.
“the total number of users whose data may have been compromised is 80,700”
Cryptopolitan reported that the newly exposed records involve orders placed by U.S. customers between November 2019 and August 2021, and that Trezor said its systems were not compromised while the breach was conducted purely from the logistics end.

AMBCrypto said Trezor received written assurances from ShipMonk that older order records had been securely deleted, but that “more than 80,000 customers have been impacted” after the latest disclosure.
Trezor also said the newly identified customers were contacted directly by email, and that the exposed information includes names, email addresses, phone numbers, shipping addresses, and order numbers.
The expanded scope contradicts the earlier August disclosure that involved 13,689 customers, which Trezor said was bounded by a 90-day data deletion policy credited with limiting the number of impacted users.
Assurances questioned, scams loom
Trezor said it was “very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” after ShipMonk provided assurances tied to its contract and data policy.
Protos quoted Trezor saying, “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” in line with the company’s data policy.

Trezor warned that leaked customer contact and order details can be used to tailor phishing and social engineering, including fake emails, fraudulent calls, and physical letters aimed at stealing seed phrases.
Cryptopolitan also described a prior pattern of targeting, noting that in February owners of Trezor and Ledger wallets received forged letters printed with holograms, QR codes, and fake signatures of executives.
The breach has therefore become a supply-chain problem in Trezor’s telling, because the company said its own systems, devices, private keys, and wallet backups were not exposed while the logistics end compromised customer contact and shipping data.
What’s at risk next
Trezor said the danger is targeting: the leaked records identify hardware wallet owners at specific home addresses, giving attackers a target list for phishing attempts via email, phone calls, and even snail mail.
“The danger here lies in targeting”
Cryptopolitan warned that “The danger here lies in targeting,” and tied that risk to scams that can be carried out without compromising devices or private keys.
AMBCrypto said the exposure is especially concerning because shipping addresses can be used to identify homes where hardware wallets are kept, and it described how knowing a customer’s name, orders, and contact details can be enough to impersonate Trezor.
Trezor advised customers to be wary of such attempts and to never reveal their wallet backup or enter it on a website, and it said anyone who did not receive a notification email is not believed to be affected.
Looking ahead, Trezor said it is working to introduce anonymous delivery, which it described as a way to reduce the personal information attached to hardware wallet purchases.
