Key highlights:

  • Personal information belonging to 67,000 Trezor customers in the US was exposed in a data breach involving shipping partner ShipMonk
  • Bad actors obtained details belonging to customers who ordered Trezor hardware wallets between November 2019 and August 2021
  • Trezor says ShipMonk failed to delete historical customer data despite repeated assurances that the information had been removed

Nearly one month after Trezor announced that its shipping partner ShipMonk suffered a data breach, additional findings show that the incident affected substantially more customers than initially disclosed. Trezor says the personal details of another 67,000 US-based customers were exposed, potentially making them targets for phishing, impersonation and other social-engineering attacks.

Importantly, the breach does not appear to involve Trezor hardware wallets themselves, private keys or customers' cryptocurrency holdings. Instead, the concern is that attackers now possess information identifying thousands of people who are likely to own cryptocurrency.

Personal data of 67,000 US-based Trezor users exposed

Trezor has disclosed that personal information belonging to as many as 67,000 US customers was exposed as part of the ShipMonk breach. According to a statement on X, the affected customers ordered Trezor hardware wallets between November 2019 and August 2021 and provided personal information as part of the delivery process.

The disclosure follows a data breach involving ShipMonk in early August. Trezor initially said the incident affected around 13,000 customers who purchased devices between May 2026 and August 2026 across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.

A subsequent investigation found that the exposed dataset was considerably larger. According to Trezor, bad actors obtained names, email addresses, phone numbers and shipping addresses belonging to an additional 67,000 customers in the US.

While the leaked information does not provide attackers with direct access to customers' wallets or cryptocurrency, it could make affected users attractive targets for highly tailored scams. Fraudsters could use the information to impersonate Trezor or other cryptocurrency companies through convincing emails, phone calls, letters or other forms of communication designed to trick users into revealing recovery seeds, passwords or other sensitive information.

The exposure of shipping addresses could also create physical-security concerns because the leaked database identifies individuals who have previously purchased cryptocurrency hardware wallets.

Trezor said it has contacted affected customers by email and urged them to remain particularly cautious about unsolicited communications.

“Please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security,” read the warning.

Trezor blames ShipMonk for retaining customer data

In its statement, Trezor blamed ShipMonk for the scale of the breach. According to the hardware wallet manufacturer, it repeatedly instructed the logistics provider to delete historical customer information and received written assurances that the data had been removed.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of data,” said Trezor. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

Trezor has also outlined measures intended to reduce the amount of personally identifiable information connected to future hardware wallet purchases. The company is preparing to introduce an Anonymous Delivery option, with an initial rollout in the EU in September followed by a planned US launch before the end of the year.

The feature is designed to allow customers to purchase hardware wallets while minimizing the connection between an order and their home address or real-world identity. Trezor says customers will be able to use nicknames and receive devices in unbranded packaging, while cryptocurrency payments will provide another option for users seeking greater privacy.

The incident highlights a broader security challenge facing cryptocurrency users. Even when hardware wallets and private keys remain secure, leaks involving customer databases can reveal valuable information to criminals, allowing them to identify likely cryptocurrency holders and target them with increasingly sophisticated social-engineering attacks.

The hardware wallet sector has faced several unrelated security incidents in recent months, including the Coldcard hardware exploit that resulted in the theft of more than $116 million worth of BTC from affected users.