Hardware cryptocurrency wallet maker Trezor has disclosed that approximately 14,000 of its customers had their shipping information exposed in a data breach at ShipMonk, a third-party logistics and fulfillment company used for order processing. The stolen records include names, physical addresses, email addresses, and phone numbers — personal identifiable information (PII) that creates real-world security and social engineering risk for the affected individuals.
What Happened
The breach originated at ShipMonk, not Trezor's own infrastructure. ShipMonk is an e-commerce fulfillment provider that handles warehousing, order packing, and shipping on behalf of merchants — in this case, managing the physical delivery of Trezor hardware wallets. Hackers targeting ShipMonk gained access to customer shipping records, which by nature contained the contact and address details of buyers.
Trezor was informed of the incident and began notifying affected customers, advising them to remain vigilant against phishing attempts and unsolicited contact claiming to be from Trezor or ShipMonk.
What Was Stolen
The compromised data includes:
- Full names
- Physical shipping addresses
- Email addresses
- Phone numbers
Critically, no cryptocurrency private keys, wallet seeds, or financial data were exposed. Trezor hardware wallets store cryptographic secrets locally on the device in secure elements, completely isolated from any cloud or fulfillment service. The breach does not grant attackers any ability to access or drain victims' cryptocurrency holdings directly.
Why This Still Matters
While the breach did not expose wallet seeds or crypto assets, the leaked data enables targeted attacks against a known population of hardware wallet owners — a group that, by definition, likely holds significant cryptocurrency assets.
Phishing and social engineering risk is elevated. Armed with a victim's name, address, phone, and email — plus the knowledge that they own a Trezor device — attackers can craft convincing spear-phishing lures. Common follow-on attack patterns include:
- Fake Trezor support emails urging users to "verify" or "resync" their wallet by entering their recovery seed on a fraudulent website
- SMS phishing (smishing) to phone numbers in the leaked dataset
- Physical mail scams — since addresses were exposed — directing victims to fake support portals
- SIM-swapping attacks using the combination of phone number and address for identity verification fraud
These phishing vectors are especially dangerous because hardware wallet users are specifically targeted by threat actors who know the payoff (access to crypto) can be immediate and irreversible.
Recommendations for Affected Users
If you purchased a Trezor device and may be in the affected cohort:
- Never enter your recovery seed online — Trezor will never ask for your 12/24-word seed phrase via email, phone, or any website outside the physical device itself.
- Be skeptical of unsolicited contact from parties claiming to be Trezor, ShipMonk, or shipping carriers.
- Enable two-factor authentication on your email account to reduce the impact of credential theft.
- Monitor for phishing domains targeting Trezor users — browser extensions like PhishFort can help flag lookalike sites.
- Watch for SIM-swap indicators — unexpected loss of cellular service or carrier notifications about SIM changes warrant immediate action.
The Bigger Picture: Third-Party Supply Chain Risk
This incident is a recurring pattern in the cryptocurrency hardware wallet space. In 2020, Ledger suffered a massive data breach through its e-commerce provider that exposed over 270,000 customer records — data that was subsequently dumped on hacker forums and used in sustained phishing campaigns for years after. Trezor itself has faced phishing campaigns exploiting prior exposure of customer lists.
The ShipMonk breach underscores the reality that any data shared with a third-party fulfillment or logistics provider is only as secure as that provider's defenses. Hardware wallet makers holding strong security postures on their own infrastructure can still expose customers through partners in the order fulfillment chain.
Organizations handling sensitive customer data — especially in high-value verticals like cryptocurrency — need to enforce strict vendor security requirements, minimize the data shared with logistics partners, and ensure breach notification SLAs are contractually defined.