Digital Wallet

Story: Trezor Data Breach Exposes 67,000 U.S. Customers Due to ShipMonk’s Oversight

By Sakamoto Nashi

1 / 15

ShipMonk at the Heart of the Problem. The partnership with ShipMonk — which handles order processing for Trezor — is directly to blame.

2 / 15

The Ledger Precedent and Its Impact on Trust. The incident is reminiscent of what happened with Ledger in 2020.

3 / 15

Trezor is facing a significant issue. The Prague-based company, known for its crypto hardware wallets, has just admitted that the data breach announced this summer is far more…

4 / 15

The data in question comes from orders placed between November 2019 and August 2021. Not recent orders. Data that, according to Trezor, should have been destroyed long ago.

5 / 15

In August, Trezor reported an initial breach affecting 11,742 customers from several countries, including the United States, the United Kingdom, and Brazil.

6 / 15

The partnership with ShipMonk — which handles order processing for Trezor — is directly to blame. Trezor claims to have received written guarantees of data deletion.

7 / 15

Neither Trezor nor ShipMonk has responded to questions about the situation. No joint statement, no explanation from ShipMonk on why the data remained.

8 / 15

And there's another figure that almost goes unnoticed: 1,947 customers have also had their names, cities, and emails compromised.

9 / 15

Trezor says it is directly contacting all involved customers. That's the minimum. But it doesn't address the central question: how are data that were contractually supposed to be…

10 / 15

Read also: OpenAI Faces Consequences After 18,000 Agent Posts on DseWiki

11 / 15

The incident is reminiscent of what happened with Ledger in 2020. Trezor's direct competitor suffered a breach via Global-e, a payment partner.

12 / 15

Trezor knows this. Hence the urgency to contact the 67,000 customers directly rather than letting the information leak through the media.

13 / 15

The problem with leaks related to subcontractors is that the manufacturer loses control as soon as the data leaves its infrastructure.

14 / 15

SatoshiLabs continues its investigation. No timeline announced, no details on what this concretely means for the partnership with ShipMonk. Will Trezor cut ties?

15 / 15

What is clear: the chain of responsibility between a hardware manufacturer and its third-party logistics partners is a huge blind spot in the industry.

The Currency Analytics

Want the full story?