Clear, fast crypto news
BrefCryptoCrypto · Bitcoin · Africa
Menu
Crypto News

Crypto: Trezor Data Breach Expands to 67,000 More Customers

Trezor reveals that the names, phone numbers and addresses of 67,000 additional US customers were exposed at ShipMonk. Private keys remain safe.

Trezor customers’ delivery data is exposed while private keys remain protected
The ShipMonk breach exposed Trezor customers’ contact details, but not their private keys or recovery phrases.

The data breach affecting Trezor customers is far larger than initially announced. The hardware wallet maker has revealed that 67,000 additional US customers had their personal information exposed at its logistics provider, ShipMonk. Names, email addresses, phone numbers, delivery addresses and order numbers are affected. Private keys were not compromised.

Crypto: 67,000 More Customers Affected

Trezor initially announced in August that 13,689 customers were affected. The discovery of 67,000 additional victims brings the total number involved in the incident to more than 80,000 people.

This new breach comes as vulnerabilities affecting hardware wallets have already reignited the debate over the security of self-custody.

The newly identified data concerns US customers who ordered Trezor products between November 2019 and August 2021.

This is where the incident becomes particularly embarrassing.

Trezor says it repeatedly asked ShipMonk to delete this old information and received written confirmations that this had been done. Its policy normally requires logistics partners to delete or anonymize order data after 90 days.

In its official update, Trezor now acknowledges that the data was still present in ShipMonk’s systems.

Bitcoin Remains Safe

The hardware wallet itself was not hacked.

Trezor’s systems, devices, private keys and recovery phrases were not exposed. A hacker therefore cannot use this database directly to move a user’s bitcoin.

The risk lies elsewhere: social engineering.

With a name, address, phone number and even the number of a genuine Trezor order, a scammer can craft a particularly convincing message. A fake security email, phone call, letter or technical support request may be all it takes for the victim to make a mistake.

This scenario echoes the malware and phishing campaigns already targeting wallets and exchange accounts.

Trezor reiterates a simple rule: no one working for the company will ask for a wallet’s recovery phrase. It should never be entered on a website received by email or shared with someone claiming to be support staff.

The Physical Address Is the Real Problem

An exposed email address is inconvenient. A physical address linked to the purchase of a hardware wallet is far more sensitive.

It may indicate that someone potentially owns cryptocurrency and directly reveal their place of residence. Trezor has also acknowledged a possible physical security risk for the affected customers.

The company is now preparing a system called “Anonymous Delivery.” It is expected to offer options including locker pickup, neutral packaging, a generic sender and the automatic deletion of delivery identifiers after receipt. The launch is planned for Europe in September and for the United States by the end of 2026.

Above all, the incident is a reminder that self-custody depends on more than a wallet’s cryptographic strength. Phishing campaigns are becoming sophisticated enough to exploit legitimate services and personal data.

Trezor customers’ bitcoin was not stolen. Their anonymity, however, has taken a serious hit.

À propos de l’auteur

Gregoire Lacroix

Gregoire Lacroix

Grégoire Lacroix est analyste et rédacteur chez BrefCrypto, spécialisé dans les cryptomonnaies et les marchés numériques. Il se concentre sur Bitcoin, l’analyse de marché, les cadres réglementaires et l’adoption réelle de la blockchain. Son travail privilégie une lecture stratégique et factuelle, orientée usage et impact économique. Il apporte un regard expert sur l’écosystème crypto africain, entre opportunités, risques et structuration du marché.