Trezor Customer Breach Expands After Shipping Vendor Exposes 67,000 Records
Hardware wallet maker Trezor revealed a logistics vendor breach exposed personal information for approximately 67,000 additional US clients.

Hardware wallet provider Trezor is managing the fallout from a security incident after discovering that a third-party logistics partner exposed the personal details of approximately 67,000 additional United States customers. The hardware wallet security breach stems from historical customer order data retained in the systems of shipping partner Shipmonk.
As reported by Bitcoin.com News, the compromised records pertain to orders placed by US customers between November 2019 and subsequent fulfillment periods. Trezor stated that the customer records were supposed to have been purged from third-party vendor databases in accordance with data retention agreements, but instead remained accessible within the contractor's internal infrastructure.
The exposed data includes customer names, shipping addresses, email contacts, and phone numbers associated with physical hardware device shipments. Trezor emphasized that the security breach did not impact private keys, recovery seed phrases, or device firmware, which remain cryptographically isolated from external shipping databases.
Supply chain and vendor data leaks present persistent risks for cryptocurrency users, as malicious actors frequently leverage compromised contact information to conduct targeted phishing campaigns and social engineering attacks against hardware wallet holders.
Security specialists advise affected users to remain exceptionally vigilant against unsolicited communications, fake firmware update notifications, and suspicious delivery inquiries attempting to harvest confidential passphrases or wallet credentials.
Trezor is continuing to audit third-party logistics relationships and has pledged to enforce stricter data verification and deletion protocols to prevent similar exposure incidents across its distribution chain.
Key takeaways
- A breach at logistics partner Shipmonk exposed personal data of roughly 67,000 US Trezor buyers.
- Compromised information includes shipping addresses and contact details from orders dating to 2019.
- Private keys and hardware wallet firmware were not compromised in the vendor data leak.
