What to Know

  • Trezor said nearly 14,000 customers were affected after fulfillment partner ShipMonk suffered unauthorized access to its systems.
  • The exposed data included names, email addresses, phone numbers and shipping addresses for 11,742 customers.
  • Names, cities and email addresses of another 1,947 customers were also exposed.
  • The affected customers were located across the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.
  • Trezor said its own systems were not compromised and its hardware wallet devices remain secure.
  • The company said customers who purchased through Amazon were not affected because those orders are handled by a separate partner.
  • Trezor said it has no confirmed cases of the exposed data being published, shared or offered for sale yet.
  • The company warned that affected customers may face higher risks of phishing attempts by email, phone or post.
  • The incident is the first breach in Trezor’s 13-year history to expose customer phone numbers and shipping addresses.

Trezor Customers Face New Phishing Risk After ShipMonk Incident

Trezor has warned nearly 14,000 customers after fulfillment partner ShipMonk suffered unauthorized access to its systems, exposing sensitive order-related information tied to hardware wallet purchases. The incident adds another security concern for crypto users who rely on cold storage devices to protect digital assets but may still be vulnerable when personal information linked to purchases is compromised through outside vendors.

The hardware wallet maker said the exposed information included names, email addresses, phone numbers and shipping addresses for 11,742 customers. A separate group of 1,947 customers had names, cities and email addresses exposed, bringing the estimated number of affected customers to nearly 14,000. The impacted customers were across the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor emphasized that its own infrastructure was not compromised and that its crypto wallet devices remain secure. The company also said that internal firmware and on-device cryptography have never been breached remotely to steal funds. That distinction matters for hardware wallet users because a breach of order data does not automatically mean that private keys, seed phrases or wallet balances have been accessed.

Wallets Remain Secure, But Personal Data Raises Longer-Term Concerns

The immediate technical risk to Trezor devices appears limited based on the company’s statements, but the privacy risk for affected customers is more complicated. Shipping records and contact details can be valuable to scammers because they help make fraudulent messages appear more credible. A malicious actor who knows that a person bought a hardware wallet may tailor a phishing email, phone call or mailed letter to impersonate Trezor, a crypto exchange, a bank or another trusted service.

Trezor said it notified all affected customers by email and added that customers who did not receive the message were not part of the compromised data set. The company also said customers who purchased through Amazon were not affected because those orders are fulfilled by a separate partner. Trezor further said it has no confirmed cases of the exposed data being published, shared or offered for sale yet, and that it is not aware of any scam or hack attempt linked to the incident so far.

Even without confirmed misuse, the exposure is significant because data breach risks often last far beyond the moment of unauthorized access. Once names, emails, phone numbers and physical addresses circulate, they can be reused in multiple campaigns over time. Crypto users are particularly attractive targets because criminals may assume that a person who purchased a hardware wallet holds digital assets and may be more likely to respond to urgent wallet security warnings.

Why Shipping Addresses Matter in Crypto Security

Hardware wallets are designed to keep private keys offline, reducing exposure to online compromise. However, the purchase and delivery process can create a separate trail of personal information. When that trail includes a shipping address, attackers may attempt more aggressive social engineering. They may send messages claiming that a device must be updated, that an account is at risk, or that a replacement wallet is required. In some cases, criminals have mailed counterfeit devices to victims of earlier breaches in an effort to trick users into revealing recovery phrases.

Market participants often view hardware wallets as a critical security tool, especially during periods of heightened exchange risk or increased cybercrime. Yet this incident shows that operational partners remain part of the security perimeter. A wallet can remain cryptographically secure while associated customer data becomes exposed through logistics, e-commerce or support systems. That separation is important, but it does not eliminate the practical risks created by targeted phishing.

The company said this is the first breach in its 13-year history to expose customer phone numbers and shipping addresses. Previous third-party incidents had already affected Trezor customers, including a January 2024 breach involving a third-party support portal that affected 66,000 people. Another 106,856 Trezor customers had data compromised in April 2022. The latest incident stands out because phone numbers and shipping addresses can enable more personalized contact attempts.

Broader Data Breach Wave Hits Crypto Users

The ShipMonk incident comes as data breaches remain a growing global issue. SentinelOne, a U.S. cybersecurity firm, said data breaches are at an all-time high and have increased by 17% compared with 2025, with an average of 2,090 attacks worldwide each week. It also estimated that global data breaches have been rising by 3% month over month since January.

Crypto customers can face a sharper version of the usual data breach problem because compromised records may identify them as people who own or have considered owning digital assets. Cybersecurity firm DeepStrike estimated that people lose tens of billions of dollars yearly to data breaches. In crypto, the costs can include direct theft through phishing, attempted extortion, identity abuse and the ongoing effort required to monitor suspicious contact.

Physical security is also an increasing concern for digital asset holders. Certik said in-person coercion attacks totalled $124 million in the first half of this year alone, although not all such cases can be traced to data breaches. The availability of a home address tied to a crypto product purchase may be especially unsettling for users who prioritize self-custody precisely because they want stronger control over their assets.

Ledger Incidents Show How Breach Fallout Can Persist

Trezor is not alone in facing third-party data exposure issues. Ledger, another major hardware wallet maker, suffered a data breach in January linked to its third-party e-commerce partner Global-e. Ledger also suffered a large-scale breach in 2020 affecting nearly 300,000 users. A year later, scammers sent fake Ledger devices to victims of that breach in a follow-on phishing campaign.

Those incidents demonstrate how stolen customer information can fuel long-running scams. Extortionists have leveraged home addresses to demand $700 to $1,000 in ransom, and counterfeit hardware devices have been mailed directly to victims. For hardware firms, managing the long-tail legal, remediation and brand fallout from a major customer leak is estimated to cost over $33 million.

The lesson for the crypto industry is that custody security must extend beyond device architecture. Secure chips, firmware integrity and offline key storage are only part of the trust equation. Customer databases, shipping vendors, e-commerce providers and support platforms can also become attack surfaces. For users, the safest response is to treat unexpected messages related to wallets, recovery phrases, upgrades or urgent security action as potentially hostile unless independently verified through trusted channels.

What Affected Customers Should Watch For

Affected customers should be alert for emails, phone calls, text messages and physical mail that reference Trezor purchases, wallet security, device replacement, exchange account problems or urgent verification requests. The most dangerous messages are likely to create pressure by claiming that funds are at risk or that a user must enter a recovery phrase to prevent loss. A legitimate hardware wallet maker should not need a customer’s recovery phrase to provide support.

Customers should also be cautious about any package that appears to contain a replacement hardware wallet or accessory that was not requested. Follow-on phishing campaigns can use physical delivery to build trust, especially when attackers have accurate shipping details. If a device arrives unexpectedly, users should avoid entering recovery information into it and should verify the situation through official customer support channels.

For the broader crypto market, the incident reinforces a familiar point: self-custody reduces certain risks but does not remove every risk. A secure wallet can protect private keys, while exposed personal data can still create social engineering threats. The best defense is layered security, careful verification and a refusal to share seed phrases under any circumstance.

Frequently Asked Questions (FAQs)

What happened to Trezor customers?

Trezor said nearly 14,000 customers had personal information exposed after fulfillment partner ShipMonk suffered unauthorized access to its systems.

What customer information was exposed?

The exposed data included names, email addresses, phone numbers and shipping addresses for 11,742 customers, along with names, cities and email addresses for another 1,947 customers.

Were Trezor wallets hacked?

Trezor said its own systems were not compromised and that its hardware wallet devices remain secure. The company also said its internal firmware and on-device cryptography have never been breached remotely to steal funds.

Which countries were affected?

Affected customers were located across the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.

Were Amazon customers affected?

Trezor said customers who purchased through Amazon were not affected because those orders are fulfilled by a separate partner.

Has the stolen data been sold or published?

Trezor said it has no confirmed cases of the exposed data being published, shared or offered for sale yet, and it is not aware of any scam or hack attempt linked to the incident so far.

Why is exposed shipping data risky for crypto users?

Shipping data can help scammers create more convincing phishing attempts by email, phone or post. It may also identify a person as someone who purchased a crypto hardware wallet.

What should affected users avoid doing?

Users should avoid sharing recovery phrases, entering seed words into unexpected websites or devices, responding to urgent wallet security messages without verification, or trusting unsolicited replacement device offers.

Has Trezor had other third-party breaches?

Satoshi Labs, the company behind Trezor, reported a third-party support portal breach in January 2024 that affected 66,000 people, and another 106,856 Trezor customers had data compromised in April 2022.

Photo by Alesia Kozik on Pexels