Trezor warns 14,000 customers after fulfilment partner suffers data breach

Third-party breach exposes shipping addresses of 14,000 Trezor buyers

By Olivier Acuna|Edited by Cheyenne Ligon

3min read

Share this article

Silhouette image of a hooded figure behind three screens.  (geralt/Pixabay)

Summary

ShipMonk, Trezor’s fulfillment partner, suffered unauthorized access to its systems, affecting nearly 14,000 customers’ data, the cold storage crypto wallet firm reported Thursday.

Trezor said the names, email addresses, phone numbers and shipping addresses of 11,742 customers had been compromised. It also said the names, cities and email addresses of another 1,947 customers were also breached, bringing the estimated number of victims to nearly 14,000 across the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.

“We have some difficult news to share,” Trezor said Thursday on X. “Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.”

The Trezor-related security hack comes as global data breaches are at an all-time high, according to SentinelOne, a U.S. cybersecurity firm. It said that this year, data breaches have increased by 17% compared with 2025, with an average of 2,090 attacks worldwide each week. It is also estimated that global data breaches have been rising by 3% month over month since January.

The cold storage wallet manufacturing firm said it notified all affected customers via email, adding that the data of those who did not receive the message was not compromised. Trezor told CoinDesk via email it has no confirmed cases of the exposed data being published, shared, or offered for sale yet. It also said it is unaware of any scam or hack attempt linked to the incident so far. Customers who purchased through Amazon are not affected, as those orders are fulfilled by a separate partner, it added.

Trezor also said its own systems were not compromised, and crypto wallet devices remain secure. The risk is indirect, it added, saying affected customers are now more likely to be targeted by phishing attempts via email, phone, or post. Scammers could use the leaked data to impersonate banks, crypto exchanges, or Trezor itself.

People whose data is stolen in a data breach remain at risk for years after the hacking event. Once stolen logistics records are sold or published online, cybercriminals continually repurpose the data for new scams. Extortionists have leveraged home addresses to demand $700 to $1,000 in ransom and mail counterfeit devices directly to victims. Managing the long-tail legal, remediation, and brand fallout from a major customer leak is estimated to cost hardware firms over $33 million.

Crypto holders are also increasingly at risk of physical attacks. In-person coercion attacks have totalled $124 million in the first half of this year alone, although not all can be traced back to a data breach, according to Certik. Cybersecurity firm DeepStrike estimated the amount of money people lose to data breaches into the tens of billions of dollars yearly.

Trezor said this was the first breach in its 13-year history to expose customer phone numbers and shipping addresses. However, Satoshi Labs, the company behind Trezor, reported that a third-party support portal’s security had been breached in January 2024, affecting 66,000 people. Another 106,856 Trezor customers’ data was compromised in April 2022. Trezor’s internal firmware and on-device cryptography have never been breached remotely to steal funds.

Ledger, the maker of one of the most popular hardware wallets in crypto, suffered a data breach in January. The security breach was linked to its third-party e-commerce partner, Global-e. In 2020, Ledger suffered another large-scale breach affecting nearly 300,000 users. A year later, scammers sent fake Ledger devices to victims of that breach in a follow-on phishing campaign.


 

Leave a Reply

Your email address will not be published. Required fields are marked *