
ShipMonk hack leaked shipping data linking crypto ownership to real-world locations, enabling targeted phishing attacks against hardware wallet users.
Trezor disclosed a data breach at ShipMonk, a fulfillment partner, that exposed personal information belonging to 13,689 customers. Orders shipped between May 10 and August 8 were affected. For 11,742 people, the stolen data included full names, phone numbers, email addresses, and shipping addresses. Another 1,947 had names, cities, and emails exposed. The breach spanned customers in seven countries across the United States and Europe.
The unsettling detail is that a hardware wallet purchase can create a physical security trail even when the wallet itself remains technically secure. Trezor said its own systems were not compromised. No device, private key, or wallet backup was affected, separating the incident from a direct wallet-security failure. ShipMonk told the company on Monday that an unauthorized party had accessed systems containing customer information.
Trezor's policy requiring partners to delete or anonymize order data 90 days after delivery limited the breach. Older customer records were no longer available within the compromised environment when the attacker gained access. That retention rule appears to have reduced the exposure substantially.
The company is now warning affected customers to treat unexpected communications with suspicion and never enter a wallet backup online. Trezor said customers who did not receive a notification email are not affected. The exposed information nevertheless gives attackers material that can make phishing attempts more convincing, particularly when names, phone numbers, emails, and home addresses can be combined. The risk is no longer limited to fraudulent links or messages. Personal shipping data can connect cryptocurrency ownership with a real-world location, creating a security problem that extends beyond passwords, seed phrases, and conventional account protections.
The incident is especially notable because Trezor said that in 13 years it had never previously experienced a breach exposing customer phone numbers and shipping addresses. The company's devices and backups remain untouched. Still, the compromise shows how a security perimeter can extend into logistics providers that never handle private keys. The breach shifts attention toward operational data held around hardware-wallet purchases rather than the cryptography protecting the wallets themselves.
For affected customers, the immediate challenge is managing exposure created by leaked contact and location information while avoiding targeted phishing or other social-engineering attempts. Attackers can combine the leaked shipping data with public blockchain records to identify high-value targets. Changing phone numbers and using address privacy services may be warranted for those who received large crypto holdings at their home. Trezor said it is working with law enforcement and has notified affected customers via email. The company recommends that all customers remain vigilant against unsolicited communications claiming to be from Trezor or its partners.
The breach underscores a broader supply chain vulnerability in the hardware wallet industry. Even if the cryptographic security of a device is sound, the fulfillment process can become a point of exposure. Trezor's 90-day data retention policy helped contain the damage, but the incident demonstrates that physical addresses and phone numbers are sensitive assets in a crypto context. The company has not disclosed whether it will change its data retention policies or audit third-party vendors more aggressively.
Crypto Hardware Wallet Users Targeted in Mail-Based Phishing Campaign – a related campaign shows how attackers weaponize leaked data against wallet owners.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.