
The cold storage wallet firm said 11,742 customers had names, addresses, and phone numbers stolen. Another 1,947 had partial data exposed. Trezor warned of phishing risks.
Trezor told customers Thursday that a data breach at its fulfillment partner ShipMonk had exposed personal information for nearly 14,000 people. The cold storage wallet maker said the breach affected customers in the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.
ShipMonk suffered unauthorized access to its systems, Trezor said. The company reported that 11,742 customers had their names, email addresses, phone numbers and shipping addresses compromised. Another 1,947 customers had their names, cities and email addresses exposed, bringing the total to roughly 14,000.
“We have some difficult news to share,” Trezor said on X. “Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.”
Trezor said it notified all affected customers by email. Customers who bought through Amazon are not affected because a separate partner handles those orders, the company added.
Trezor’s own systems were not compromised. The hardware wallets themselves remain secure, the company said. The risk is indirect. Affected customers are now more likely to be targeted by phishing attempts via email, phone, or post. Scammers could use the leaked data to impersonate banks, crypto exchanges, or Trezor itself.
Trezor told CoinDesk via email that it has no confirmed cases of the exposed data being published, shared, or offered for sale. It also said it is unaware of any scam or hack attempt linked to the incident so far.
People whose data is stolen in a breach remain at risk for years, cybersecurity firms have warned. Once logistics records are sold or published, criminals repurpose the data for new scams. Home addresses have been used to demand ransoms of $700 to $1,000. Counterfeit devices have been mailed directly to victims. Managing the long-term fallout from a major customer leak costs hardware firms over $33 million on average, according to industry estimates.
Crypto holders face an added risk of physical attacks. In-person coercion attacks totaled $124 million in the first half of this year alone, according to Certik, though not all trace back to a data breach. DeepStrike estimated that losses from data breaches run into the tens of billions of dollars yearly.
This is the first breach in Trezor’s 13-year history to expose customer phone numbers and shipping addresses, the company said. The parent company Satoshi Labs suffered a previous breach in January 2024 when a third-party support portal was compromised, affecting 66,000 people. Another 106,856 Trezor customers’ data was exposed in April 2022. Trezor’s internal firmware and on-device cryptography have never been breached remotely to steal funds.
Ledger, another major hardware wallet maker, suffered a data breach in January linked to its third-party e-commerce partner Global-e. In 2020, Ledger had a larger breach affecting nearly 300,000 users. A year later, scammers sent fake Ledger devices to victims of that breach in a follow-on phishing campaign.
No affected customer reported any financial loss directly tied to the incident as of Thursday evening.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.