A data breach involving logistics provider ShipMonk has expanded the number of Trezor customers whose information may have been exposed.
Trezor said approximately 67,000 additional U.S. customers were affected by the breach.
The newly identified records dated from 2019 through 2021 and included information such as names, email addresses, telephone numbers, shipping addresses and order numbers.
The company had previously disclosed an exposure involving nearly 14,000 customers.
Why This Matters to Crypto Users
A hardware wallet can protect private keys from many online attacks.
But users still interact with external companies when purchasing the devices.
That creates an important security distinction:
Wallet security ≠ personal-data security
Someone may have a perfectly secure cryptocurrency wallet while personal information connected with the purchase of that wallet is exposed.
What Information Was Exposed?
The reported information included:
- names
- email addresses
- phone numbers
- shipping addresses
- order numbers
The exposure is significant because shipping information can create additional phishing and social-engineering risks.
An attacker who knows that someone purchased a cryptocurrency hardware wallet has information that could potentially be used to construct more convincing scams.
Why Hardware-Wallet Users Should Be Careful
Users should be suspicious of unexpected communications involving:
- wallet updates
- account verification
- security alerts
- seed-phrase requests
- replacement devices
- firmware updates
Legitimate hardware-wallet companies should never require customers to provide their recovery phrase.
A recovery phrase should be treated as the master key to cryptocurrency holdings.
Personal Information Can Become a Security Risk
Crypto security discussions often focus on private keys.
But attackers can also target people.
Social engineering is often easier when criminals have background information about their target.
For example, someone receiving an email mentioning a specific wallet product may believe the message is legitimate.
That can lead to:
- phishing
- fake support calls
- malicious downloads
- seed-phrase theft
Does the Data Breach Mean Trezor Wallets Were Hacked?
Not necessarily.
The reported incident involved customer information held by a shipping provider.
That is different from compromising the cryptographic security of a hardware wallet.
Users should therefore distinguish between:
personal information exposure
and
private-key compromise.
The Supply Chain Problem
Modern hardware products depend on complex supply chains.
A company may manufacture a device, operate software infrastructure and use external companies for:
- payment processing
- logistics
- customer support
- shipping
- marketing
Each external provider creates another information environment.
That makes supply-chain security increasingly important.
What Users Should Do
Users potentially affected by a breach should remain alert to suspicious communications.
They should never:
- disclose their seed phrase
- install unsolicited software
- transfer crypto because of an email
- click suspicious wallet links
- provide private keys
They should also verify communications through official company websites and applications.
Final Takeaway
Trezor said approximately 67,000 additional U.S. customers were affected by a ShipMonk data breach involving information dating from 2019 to 2021.
The incident highlights a critical lesson:
Crypto security is not only about protecting private keys.
Personal information can also become an attack vector.
Anyone using hardware wallets should therefore treat privacy and cybersecurity as part of the same overall security strategy.