Trezor Customers Caught in a Second Wave of ShipMonk Data Leak
The crypto hardware wallet maker says 67,000 more U.S. buyers had their names, addresses and phone numbers exposed through its old shipping partner. The wallets themselves are unaffected.

Key points
- Trezor said on Friday that 67,000 more U.S. customers had personal details exposed in a breach at its former shipping partner ShipMonk.
- The leaked data covers orders placed between November 2019 and August 2021, and includes names, email addresses, phone numbers, shipping addresses and order numbers.
- No passwords, payment details, recovery seeds or wallet contents were exposed, Trezor said.
- Trezor had previously been told the data was deleted, which turned out to be wrong.
- Affected customers should expect a rise in targeted phishing attempts and physical mail scams.
Trezor, the Czech company that makes small USB-style devices for storing cryptocurrency offline, has told another 67,000 of its U.S. customers that their personal details were exposed in a breach at ShipMonk, the logistics firm it once used to post orders.
The disclosure, first reported by The Hacker News, is an unwelcome sequel. Trezor had already warned a smaller group of customers about the same ShipMonk incident. It now turns out the exposed dataset was much larger, and that assurances the data had been wiped were incorrect.
What was actually leaked?
Contact and shipping information, not anything that touches the wallets themselves. The exposed fields are customer names, email addresses, phone numbers, shipping addresses, and order numbers. The orders in question were placed between November 2019 and August 2021.
No passwords were involved. No payment card numbers. And critically for a crypto company, no recovery seeds, the secret word lists that would let an attacker drain a wallet.
A Trezor hardware wallet is a small device that stores the secret keys to someone's cryptocurrency offline, so a hacker on the internet cannot reach them. That protection is unchanged. The leak is about who bought a wallet and where it was shipped, not what is on the wallet.
How did this happen at ShipMonk?
ShipMonk is a third-party fulfilment company: businesses hand it their orders, and it packs and ships the parcels. Trezor used ShipMonk for U.S. deliveries during the 2019 to 2021 window. The breach happened inside ShipMonk's systems, not Trezor's.
This is a familiar pattern in security: the supplier gets breached, and the customer of that supplier ends up doing the apologising. Trezor said it was previously assured the affected records had been deleted. They had not been.
| Detail | Figure |
|---|---|
| Newly disclosed U.S. customers affected | 67,000 |
| Order date range | Nov 2019 to Aug 2021 |
| Data exposed | Name, email, phone, address, order number |
| Wallet security impact | None |
| Source of breach | Shipping provider ShipMonk |
Should Trezor owners be worried?
The wallets are safe. The bigger risk is social engineering, meaning scams that use the leaked details to sound convincing. Anyone on that shipping list is now a known crypto owner with a verified home address, which is exactly the profile fraudsters and, occasionally, physical thieves look for.
Expect emails that name-drop an old order number. Expect texts claiming a delivery issue. Expect the occasional letter in the post pretending to be from Trezor support asking you to "verify" your wallet by typing in your recovery seed. That last one is the classic crypto trap: Trezor will never ask for the seed, and typing it into any website or app hands over the coins.
If a message pushes you to install software, open an attachment, or share your 12 or 24 recovery words, treat it as hostile. Go to the Trezor website by typing the address yourself.
The wider point
Supply-chain leaks like this rarely make the security world's front page, because no clever exploit is involved. There is no zero-day, meaning a previously unknown software flaw, and no ransomware crew taking credit. Just a fulfilment vendor holding customer records for years longer than anyone realised, and an assurance of deletion that did not hold up. For a company whose customers are, by definition, holders of bearer assets, that ordinary failure carries an unusually sharp edge.



