Hardware wallet maker Trezor has revealed that a data breach at its US shipping partner exposed the personal details of an additional 67,000 American customers, dramatically widening the scope of an incident first disclosed in August.
What Was Exposed
Trezor disclosed the expanded breach in a post on X, citing the latest update from its logistics provider, ShipMonk. The affected customers had placed orders between November 2019 and August 2021. According to Trezor, the compromised data includes full names, email addresses, phone numbers, shipping addresses, and order specifics.
Trezor said it had previously received written assurances from ShipMonk that the data from those orders would be deleted. The company placed blame squarely on the shipping provider for failing to follow through on that commitment. Trezor stressed that its own internal systems were not compromised in the incident.
Phishing Risk Now Elevated for 67,000 Users
While no Trezor wallet software or firmware was touched, the leaked data creates a clear pathway for malicious actors to launch targeted phishing campaigns. Attackers could impersonate Trezor and attempt to trick affected users into revealing their seed phrases, which control access to crypto wallets. Once a seed phrase is obtained, a wallet can be fully drained without any further technical exploit.
A Growing Pattern of Exposure
This disclosure marks the second major data incident tied to third-party handling of Trezor customer information. In August, Trezor initially estimated that 14,000 users had been exposed through ShipMonk. Friday’s disclosure covers a further 67,000, on top of that earlier count rather than replacing it.
Separately, in January 2024, Trezor reported that around 66,000 users faced phishing risks after their data was accessed through the company’s support portal, covering users who had contacted support since December 2021.
Industry-Wide Phishing Toll
The risk posed by this breach sits within a broader wave of social engineering losses hitting the crypto sector. According to blockchain security firm Hacken, phishing attacks and social engineering schemes accounted for $306 million of the $482 million total lost by the crypto industry in the first quarter of the year. These attacks do not require exploiting code vulnerabilities, making exposed customer data a highly effective tool for criminals.
In July, one crypto investor lost close to $1 million after signing a malicious phishing token approval transaction on Ethereum, illustrating how costly a single successful impersonation attempt can be.
What Affected Users Should Do
– Be highly suspicious of any communication claiming to be from Trezor asking for seed phrase information.
– Never enter a seed phrase into any website, app, or form, regardless of how legitimate it appears.
– Treat any unsolicited contact referencing an order from 2019 to 2021 as a potential phishing attempt.
– Monitor wallet addresses for unauthorised activity.
Trezor has not announced any compensation or remediation programme for affected users as of this report.


