Trezor has confirmed that a data breach tied to its shipping provider is far larger than first reported. Another 67,000 US customers now have their personal details exposed to potential attackers. For hardware wallet owners, that opens the door to targeted phishing aimed squarely at their crypto holdings. A hardware wallet keeps keys safe from online hacking, but it can't stop someone from handing over access after reading a convincing enough email.
What actually happened?
Back in August, Trezor said only 14,000 customers were affected. On Friday, the company revised that estimate to 67,000 users who had ordered devices between November 2019 and August 2021. The breach traces back to its logistics partner, ShipMonk.
The exposed records included names, emails, phone numbers, shipping addresses and order details. That's more than enough to craft a convincing message pretending to be Trezor support.
That's nearly a fivefold jump in the estimate within a single month. A revision that large usually means the company underestimated the scope early on, or received the data from its partner in batches rather than one full report.
Why is the shipping provider to blame?
Trezor stressed that its own systems were never compromised. The fault sits entirely with ShipMonk, which held onto order data far longer than the two companies had agreed. This isn't the first such incident either. Back in January 2024, Trezor warned of a phishing risk for 66,000 users who had contacted support after December 2021, though that earlier case involved a different leak channel.
For customers, the distinction barely matters. In both cases, attackers end up with exactly the details needed for a convincing scam: a real name, address and order number.
Hardware wallet makers rarely ship devices themselves and almost always hand logistics to outside companies like ShipMonk. That's standard practice across the whole industry, so this problem isn't unique to Trezor. Each such partner becomes a separate point of entry for a leak, and the brand printed on the box ends up answering to customers even when its own code and servers were never touched.
Why does this threaten Bitcoin holders?
Phishing and social engineering don't require breaking any code or exploiting a device flaw. All it takes is tricking someone into typing their seed phrase into a fake website or a cloned app. Whoever gets those 12 or 24 words gets full access to the Bitcoin and other assets sitting in that wallet, no technical hack required.
These attacks run on trust and personal detail, so every fresh leak of wallet owner data raises the risk across the whole industry, not just for one device brand. In July, one investor lost nearly $1 million after signing a malicious token approval on Ethereum, just one example of how costly a single careless click can get.
Those non-technical, psychological attacks accounted for more than half of everything lost in the first quarter. Leaking Trezor customers' personal data hands scammers fresh material for the next wave of fake calls and emails.
What does this kind of attack usually look like?
The most common script is simple. Someone calls or emails about a "problem with your recent order" or the "need to update your firmware." The message asks the person to click a link and enter their wallet details to verify something. In some cases, scammers even mail a fake device that looks like a real Trezor, with instructions to "activate" it using a seed phrase.
No legitimate manufacturer will ever ask for a seed phrase over the phone, in a chat, or by email. That's the one rule worth remembering for good, no matter how convincing the request sounds.
How can affected device owners protect themselves?
- Never type a seed phrase anywhere except the device itself: not on a website, not in a support form, not in a phone app.
- Treat any email or call that references your order number or shipping address with suspicion.
- Check the official domain manually instead of clicking links from an email, even one that looks legitimate.
- For larger holdings, consider a second hardware wallet from a different maker if the device was ordered during that window.
- Turn on two-factor authentication wherever possible for email and any account tied to the device order.
What should Trezor owners do next?
The company says it will notify affected users individually by email. Until that message arrives, treat anything referencing this breach as suspicious by default. A hardware wallet stays safe on its own, but only for as long as the owner never hands the seed phrase to another person or site.
For the hardware wallet industry, this case is another reminder that crypto security doesn't stop at the chip inside the device. Logistics, support staff and any outside contractor are part of the security perimeter too, and that's exactly where companies need to check data-deletion contracts as carefully as they check their own firmware code.




Comments
Your email address will not be published. Required fields are marked *