INSIGHTS

Trezor Says ShipMonk Breach Exposed Names, Phone Numbers and Addresses of 13,689 Customers

Share:

Hardware wallet maker Trezor says a data breach at its third-party shipping provider ShipMonk exposed the names, phone numbers and home addresses of 13,689 customers, a disclosure the company framed as a logistics-vendor incident rather than a compromise of its wallets or user funds.

Trezor attributed the exposure to ShipMonk, the fulfillment partner that handles order shipping, and said the incident affected customer contact and address records, according to the company’s disclosure. The figure of 13,689 affected customers defines the reported scale of the exposure.

The disclosure is a company statement about a vendor breach, not an independently verified forensic finding. Trezor has positioned the event as originating outside its own systems, at the shipping provider handling deliveries. For related coverage, see Tether Says Big Four Audit Is Complete for $180B USDT.

Which Customer Details Were Exposed

The reported exposed fields are names, phone numbers and home addresses, per Trezor’s account of the ShipMonk incident. Each is personally identifying data tied to a customer’s identity and physical location. For related coverage, see Solana Stake Outage: Marinade Says 29% Went Offline After Routing Fault.

Trezor’s framing does not indicate that seed phrases, wallet passwords or funds were exposed. The incident, as described, concerns the offline contact and shipping records held by the fulfillment vendor, not the cryptographic material stored on a Trezor device. For related coverage, see Tokenization Stocks Slip After SEC Delay Slows Crypto's Wall Street Push.

That distinction matters for a hardware wallet, where the device’s core security promise is that recovery seeds never leave the device. The exposed data is the kind held in an order and delivery database. For related coverage, see Israel's largest bank to offer crypto trading with Galaxy.

Why the Incident Matters for Trezor Customers

Home address exposure raises a direct physical privacy concern for the affected customers, because it links a named individual to a hardware wallet purchase and a residential location. Phone number exposure adds a channel for phishing and social engineering attempts.

Contact-data leaks tied to crypto holders have repeatedly fed targeted scam campaigns, a pattern that also surfaces in broader crypto security failures such as the hiring and infiltration risks now scrutinized across the industry. Trezor’s disclosure names its own customers as the exposed group.

The company shared the notice through its official channels, including a post on X. Beyond the reported scope, Trezor has not detailed confirmed remediation steps in the material available here, and this account rests on the company’s own statement rather than an independent audit.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.