Trezor disclosed on Thursday that nearly 14,000 customers had personal data exposed after ShipMonk, the hardware-wallet maker's fulfilment partner, suffered an unauthorised access to its systems. The leak hits 11,742 customers whose names, email addresses, phone numbers and shipping addresses were compromised, plus another 1,947 whose names, cities and emails were exposed, spanning the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor stressed that its own infrastructure and on-device cryptography were not breached and that no funds are at risk from the leak itself. The risk is downstream: phone numbers and home addresses are exactly what phishing crews, mail-extortion rings, and physical-coercion attackers need to escalate from digital spam to counterfeit-device drops and in-person pressure.
Why it matters
This is the first data breach in Trezor's 13-year history to expose customer phone numbers and shipping addresses. Earlier incidents, a January 2024 third-party support portal breach affecting 66,000 users and an April 2022 leak of 106,856 customers, stopped at email. Adding a physical address and a phone number to the file makes the dataset dramatically more dangerous, and the breach lands against a backdrop in which global data breaches are up 17% year-on-year, according to cybersecurity firm SentinelOne.
Market impact
Trezor said it has no confirmed cases of the data being published, shared, or offered for sale yet, and that Amazon customers were unaffected because orders there are fulfilled by a separate partner. Rival hardware-wallet maker Ledger has lived through this exact pattern: a 2020 breach affecting nearly 300,000 users produced a follow-on campaign a year later in which scammers mailed fake Ledger devices to victims. Industry estimates put long-tail remediation, legal, and brand costs from a major customer leak at more than $33 million, on top of a separate trend Certik puts at $124 million of in-person coercion losses in the first half of the year. The watch-item for affected customers is direct mail, phone-based impersonation, and home-targeted extortion attempts in the months ahead.
Frequently asked questions
-
What data was exposed in the Trezor breach via ShipMonk?
Names, email addresses, phone numbers and shipping addresses for 11,742 customers, plus names, cities and emails for another 1,947 customers, across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
-
Were Trezor wallets or customer funds affected by the breach?
No. Trezor said its own systems were not compromised and on-device cryptography remains intact. The risk is indirect, since leaked contact data can be used to target customers with phishing, counterfeit-device mail, or home extortion attempts.
-
How does this Trezor breach compare with earlier leaks?
It is the first in Trezor's 13-year history to expose phone numbers and shipping addresses. Earlier incidents in January 2024 (66,000 affected via a support portal) and April 2022 (106,856 customers) stopped at email addresses.
-
How does this compare to the Ledger data breaches?
Rival hardware-wallet maker Ledger suffered a 2020 breach affecting nearly 300,000 users that produced a follow-on campaign a year later in which scammers mailed fake Ledger devices to victims, plus a January breach via partner Global-e.
-
What should affected Trezor customers watch for now?
Trezor said no confirmed cases of the data being published, shared, or sold have emerged yet, but customers should watch for direct mail, phone-based impersonation, and home-targeted extortion attempts in the months ahead.
CoinDesk