BNB $723.02 -0.07%
XRP $1.40 -3.32%
ETH $2,452.16 -2.36%
BTC $79,639.39 -1.61%
BNB $723.02 -0.07%
XRP $1.40 -3.32%
ETH $2,452.16 -2.36%
BTC $79,639.39 -1.61%
BREAKING
Digital Wallet

Trezor Data Breach Exposes 67,000 U.S. Customers Due to ShipMonk’s Oversight

Trezor Expose 67 000 Clients Américains Après que ShipMonk Garde des Données Promises Effacées
Trezor Data Breach Affects 67,000 U.S. Customers as ShipMonk Fails to Delete Records

Community Trust ScoreLikely Real

79%
Real
Likely Real38 votes
Updated 1 hour ago

Trezor is facing a significant issue. The Prague-based company, known for its crypto hardware wallets, has just admitted that the data breach announced this summer is far more extensive than initially reported — an additional 67,000 American customers have had their names, emails, phone numbers, shipping addresses, and order numbers exposed.

The data in question comes from orders placed between November 2019 and August 2021. Not recent orders. Data that, according to Trezor, should have been destroyed long ago. The logistics partner ShipMonk had provided written assurances — in line with the contract, according to Trezor — that it would erase this information. It did not. And that’s where everything went wrong.

In August, Trezor reported an initial breach affecting 11,742 customers from several countries, including the United States, the United Kingdom, and Brazil. It was thought to be limited. Not quite. The new announcement multiplies the scope by almost six, significantly increasing the risk for the affected customers.

Advertisement

ShipMonk at the Heart of the Problem

The partnership with ShipMonk — which handles order processing for Trezor — is directly to blame. Trezor claims to have received written guarantees of data deletion. ShipMonk did not delete. Period. Trezor’s parent company, SatoshiLabs, has launched an investigation into the incident, but no public conclusions have been shared yet.

Neither Trezor nor ShipMonk has responded to questions about the situation. No joint statement, no explanation from ShipMonk on why the data remained. Total ambiguity from the logistics operator.

And there’s another figure that almost goes unnoticed: 1,947 customers have also had their names, cities, and emails compromised. A separate group, likely with more limited exposure, but affected nonetheless.

Trezor says it is directly contacting all involved customers. That’s the minimum. But it doesn’t address the central question: how are data that were contractually supposed to be deleted still accessible years later?

The Ledger Precedent and Its Impact on Trust

The incident is reminiscent of what happened with Ledger in 2020. Trezor’s direct competitor suffered a breach via Global-e, a payment partner. Ledger customers received emails notifying them of the breach — and for months afterward, some reported targeted phishing attempts, threats, and personalized scams using their physical addresses. Data breaches in the crypto hardware sector are not just a line in a GDPR report. It’s a physical risk because people know you likely hold digital assets.

Trezor knows this. Hence the urgency to contact the 67,000 customers directly rather than letting the information leak through the media.

The problem with leaks related to subcontractors is that the manufacturer loses control as soon as the data leaves its infrastructure. ShipMonk handles logistics — not crypto, not wallet security. But it processes sensitive customer data from a company whose buyers are, by definition, digital asset holders. It’s a prime target.

SatoshiLabs continues its investigation. No timeline announced, no details on what this concretely means for the partnership with ShipMonk. Will Trezor cut ties? Probably under consideration. Not clear yet.

What is clear: the chain of responsibility between a hardware manufacturer and its third-party logistics partners is a huge blind spot in the industry. Trezor is not the first to suffer from this. It probably won’t be the last either.

Affected customers — the 67,000 as well as the 11,742 announced in August — should expect to receive direct communication from Trezor. The company says it has done so or is in the process of doing so. What they do with this information afterward is their choice. But changing email addresses, enabling two-factor authentication everywhere, and staying vigilant against targeted phishing attempts — that’s the minimum in such a situation.

SatoshiLabs has not said when the investigation will conclude. ShipMonk has not explained why the data were not deleted. And 67,000 people are waiting for answers that no one seems in a hurry to provide.

Frequently Asked Questions

How many Trezor customers were affected by this data breach?

In total, an additional 67,000 American customers are affected, in addition to the 11,742 customers announced during an initial disclosure in August. Additionally, 1,947 customers have had their names, cities, and emails compromised separately.

What period do the exposed data in the Trezor breach cover?

The data come from orders placed between November 2019 and August 2021, and include names, emails, phone numbers, shipping addresses, and order numbers.

Why is ShipMonk at the center of the Trezor incident?

ShipMonk, Trezor’s logistics partner, had given written assurances that it would delete customer data in accordance with their contract. It did not, leading to the exposure of tens of thousands of customers’ information.

Why It Matters

The Trezor data breach highlights ongoing vulnerabilities in the crypto hardware sector, raising concerns about customer privacy and trust in a market that relies heavily on security. As the number of affected customers grows, it underscores the importance of robust data management practices, especially for companies handling sensitive information within the digital asset ecosystem. This incident may prompt users to reconsider their security choices, potentially impacting the adoption of hardware wallets in a landscape already wary of cybersecurity threats.

Community Trust IndexHigh Confidence
79%
Real
Real79%21%Fake
38 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories