Loading prices…
🩸BEARISH

Trezor Warns ShipMonk Breach Exposed 67,000 More Customers

The expanded exposure raises phishing and physical-security risks for hardware-wallet users, while Trezor says its own systems and hardware wallets remain secure.

Trezor said ShipMonk notified it on Sept. 2 that a shipping-provider breach affected approximately 67,000 additional U.S. customers, beyond the nearly 14,000 initially disclosed. The newly identified order records cover purchases made between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. Trezor said its systems were not compromised and its hardware wallets remain secure. It emailed affected customers and warned of phishing, fraudulent calls and letters, plus possible physical-security risks.

Why it matters

Exposed home addresses can connect a hardware-wallet user to a real-world location and crypto ownership, creating risks beyond phishing. Trezor said it repeatedly asked ShipMonk to delete customer data and received written assurances that the records had been removed under its contract and data policy. The expanded disclosure shows the data remained in ShipMonk's systems.

That failure matters beyond Trezor. A 2020 Ledger breach exposed information on more than 270,000 customers, with users later reporting scam calls and physical letters years afterward.

Market impact

The immediate impact is on privacy, personal safety and trust in fulfillment vendors, not the security of Trezor's hardware wallets. Names, contact details and addresses give scammers material for targeted social engineering, even when the device itself remains secure.

The next test is whether all affected customers can identify legitimate outreach and whether ShipMonk's deletion assurances can be verified. For hardware-wallet users, the incident shows that device security does not eliminate the risks of exposed personal information.

Frequently asked questions

  1. What information did the newly identified ShipMonk records contain?

    The records included names, email addresses, phone numbers, shipping addresses and order numbers from purchases made between November 2019 and August 2021.

  2. Did the ShipMonk breach compromise Trezor's systems or hardware wallets?

    No. Trezor said its systems were not compromised and its hardware wallets remain secure.

  3. Why do exposed addresses create extra risks for hardware-wallet users?

    A home address can connect a hardware-wallet user to a real-world location and crypto ownership, creating risks beyond phishing and possible physical-security threats.

  4. What did Trezor say about ShipMonk's data-deletion assurances?

    Trezor said it repeatedly requested deletion and received written assurances that the records had been removed. The expanded disclosure showed the data remained in ShipMonk's systems.

  5. How did the latest disclosure compare with Trezor's initial count?

    Trezor initially disclosed nearly 14,000 affected customers before identifying approximately 67,000 additional U.S. customers in the latest disclosure.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 1h ago
Open original →