Crypto

Trezor Says ShipMonk Breach Exposed 67,000 More US Customers

Trezor confirmed that an additional 67,000 US customers who ordered between November 2019 and August 2021 had their full personal details exposed after shipping partner ShipMonk failed to delete the data as promised.

⏱ 3 min read Crypto
Quick Summary
  • Trezor says 67,000 additional US customers had full personal details exposed by shipping provider ShipMonk, covering orders placed between November 2019 and August 2021.
  • Trezor blames ShipMonk for failing to delete the data despite written assurances, though Trezor's own systems were not compromised.
  • The exposed data could fuel phishing attacks impersonating Trezor in attempts to steal users' seed phrases, with phishing accounting for $306 million of $482 million in crypto losses in Q1.

Hardware wallet maker Trezor has revealed that a data breach at its US shipping partner exposed the personal details of an additional 67,000 American customers, dramatically widening the scope of an incident first disclosed in August.

What Was Exposed

Trezor disclosed the expanded breach in a post on X, citing the latest update from its logistics provider, ShipMonk. The affected customers had placed orders between November 2019 and August 2021. According to Trezor, the compromised data includes full names, email addresses, phone numbers, shipping addresses, and order specifics.

Trezor said it had previously received written assurances from ShipMonk that the data from those orders would be deleted. The company placed blame squarely on the shipping provider for failing to follow through on that commitment. Trezor stressed that its own internal systems were not compromised in the incident.

Phishing Risk Now Elevated for 67,000 Users

While no Trezor wallet software or firmware was touched, the leaked data creates a clear pathway for malicious actors to launch targeted phishing campaigns. Attackers could impersonate Trezor and attempt to trick affected users into revealing their seed phrases, which control access to crypto wallets. Once a seed phrase is obtained, a wallet can be fully drained without any further technical exploit.

A Growing Pattern of Exposure

This disclosure marks the second major data incident tied to third-party handling of Trezor customer information. In August, Trezor initially estimated that 14,000 users had been exposed through ShipMonk. Friday’s disclosure covers a further 67,000, on top of that earlier count rather than replacing it.

Separately, in January 2024, Trezor reported that around 66,000 users faced phishing risks after their data was accessed through the company’s support portal, covering users who had contacted support since December 2021.

Industry-Wide Phishing Toll

The risk posed by this breach sits within a broader wave of social engineering losses hitting the crypto sector. According to blockchain security firm Hacken, phishing attacks and social engineering schemes accounted for $306 million of the $482 million total lost by the crypto industry in the first quarter of the year. These attacks do not require exploiting code vulnerabilities, making exposed customer data a highly effective tool for criminals.

In July, one crypto investor lost close to $1 million after signing a malicious phishing token approval transaction on Ethereum, illustrating how costly a single successful impersonation attempt can be.

What Affected Users Should Do

– Be highly suspicious of any communication claiming to be from Trezor asking for seed phrase information.
– Never enter a seed phrase into any website, app, or form, regardless of how legitimate it appears.
– Treat any unsolicited contact referencing an order from 2019 to 2021 as a potential phishing attempt.
– Monitor wallet addresses for unauthorised activity.

Trezor has not announced any compensation or remediation programme for affected users as of this report.

⚖️ Our Verdict ⚖️ Watch and Wait

There is no market call in a data breach, so there is no direction to take here. What matters is practical and immediate. Anyone who ordered a Trezor in the United States between November 2019 and August 2021 should assume their name, address, phone number and order history are in criminal hands, and treat any contact claiming to come from Trezor as hostile. No wallet is compromised by this on its own, and Trezor's own systems were not breached, but the leaked information is exactly what a convincing phishing attempt needs.