Trezor Breach: 67,000 Customers' Data Exposed After Deletion Promise

·
Listen to this article~4 min
Trezor Breach: 67,000 Customers' Data Exposed After Deletion Promise

Trezor disclosed a breach at shipping partner ShipMonk affecting 67,000 U.S. customers. Exposed data includes names, emails, phones, and addresses from orders placed between 2019 and 2021. Your crypto is safe, but your privacy might not be.

Hardware wallet maker Trezor just dropped some unsettling news. On Friday, the company revealed that a data breach at its shipping partner, ShipMonk, exposed personal information belonging to another 67,000 customers in the U.S. If that sounds familiar, it's because Trezor has been down this road before. Back in 2022, a similar breach at ShipMonk affected nearly 66,000 customers. Trezor said at the time that the data had been deleted. Turns out, it wasn't. ### What Exactly Got Leaked? The exposed data includes: - Full names - Email addresses - Phone numbers - Shipping addresses - Order numbers The affected orders were placed between November 2019 and August 2021. So if you bought a Trezor during that window, there's a decent chance your info is floating around somewhere it shouldn't be. ### Your Crypto Is Safe, But Your Privacy Isn't Here's the good news: Trezor says this breach does not compromise the security of its hardware wallets. Your private keys, your crypto, your funds—all of that remains locked down tight. The devices themselves weren't touched. But let's not gloss over the bad news. Your personal data is out there. And for crypto users, that's a big deal. Unlike a credit card number, you can't just cancel your home address. This kind of information is a goldmine for phishing attacks, SIM-swapping schemes, and good old-fashioned physical threats. "This isn't just about spam emails," said one security researcher familiar with the incident. "When attackers know you own crypto and have your phone number and address, you become a target. It's that simple." ### Why This Feels Like a Broken Promise What stings most is that Trezor previously assured customers the data from the earlier breach had been deleted. Now, 67,000 more people are learning that wasn't the case. It's a tough pill to swallow for a company whose entire brand is built on security and trust. Trezor hasn't yet said exactly how this happened or why the data resurfaced. But the incident raises uncomfortable questions about how shipping partners handle sensitive customer information—and how much oversight hardware wallet companies really have over their supply chains. ### What Should You Do Now? If you're one of the affected customers, don't panic. But do take action: - Be skeptical of any unsolicited emails, calls, or texts claiming to be from Trezor or a shipping company. - Never share your seed phrase with anyone. Ever. Trezor will never ask for it. - Consider using a separate email address and phone number for crypto-related purchases going forward. - If you receive physical mail that seems suspicious, report it. ### The Bigger Picture This breach is a reminder that even the most security-focused companies can stumble when third parties are involved. Your hardware wallet might be bulletproof, but your personal data lives in databases you don't control. For now, Trezor says it's investigating and will notify affected customers. But for 67,000 people, the damage may already be done. Stay sharp out there.