Trezor, a hardware wallet maker based in Prague, has confirmed a data breach affecting almost 14,000 recent customers, exposing their personal information through a compromised third-party shipping provider.
Scope of the data breach
The incident affected 13,689 customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Individuals who placed orders within 90 days before August 8 are impacted.
Trezor stated that the breach was traced back to ShipMonk, a third-party fulfillment partner, which suffered unauthorized access to systems storing customer information. SatoshiLabs, the parent company of Trezor, is currently investigating the breach alongside ShipMonk.
Of the affected users, 11,742 had their names, email addresses, phone numbers, and shipping addresses exposed. The remaining 1,947 had only their names, city, and email address leaked.
Trezor reported that its own core systems and wallet devices have not been compromised. However, the company warned that customers whose data was leaked may face a heightened risk of phishing attacks.
Trezor explained that, despite the breach, its devices and systems remain secure, but exposed users should expect an increase in scam attempts such as fraudulent emails, phone calls, or impersonation of financial institutions and crypto platforms.
The company expressed regret for the incident and apologized to affected customers and the wider crypto community.
Mini dictionary: ShipMonk is a logistics and order fulfillment company that handles warehousing and shipping services for ecommerce businesses, including crypto hardware manufacturers like Trezor.
| Data type exposed | Customers affected | Details |
|---|---|---|
| Name, email, phone, shipping address | 11,742 | Full contact information leaked |
| Name, city, email | 1,947 | Partial details leaked |
Security risks and industry context
Trezor highlighted that scammers could exploit the compromised information to send convincing phishing emails, make deceptive phone calls, issue fraudulent letters, or impersonate legitimate financial or crypto institutions.
Trezor is recognized as one of the most widely used hardware wallets for Bitcoin and supports several other cryptocurrencies. Its parent company, SatoshiLabs, was established in 2013 and is headquartered in Prague, Czech Republic.
SatoshiLabs confirmed that investigations into the breach are ongoing and that customers will receive updates on any developments impacting their security or personal information.
Other recent incidents targeting crypto users
The crypto industry has faced several major breaches in recent years targeting hardware wallet users. In 2020, Ledger, another leading wallet manufacturer, disclosed a hack where an unauthorized party accessed its e-commerce database and marketing system, resulting in the leak of more than 1 million email addresses and sensitive details for nearly 10,000 users.
Earlier this year, Global-e, a payment partner of Ledger, informed customers of a cloud systems breach that exposed further sensitive information. Both incidents led to an increase in phishing attempts against affected customers.
Additionally, the Bitcoin community is recovering from a recent attack on Coldcard, a hardware wallet produced by Canadian company Coinkite. Last month, hackers exploited vulnerabilities to begin draining Bitcoin from these wallets, with losses initially calculated at $111 million, though some estimates suggest they may exceed $130 million as the investigation progresses.
Users of Coldcard were urged by Coinkite to move their funds as the thefts continued. Hackers reportedly focused on later production models in their attempts to access stored digital assets.





USDT
AAPL
