
Hardware wallet manufacturer Trezor announced on September 4 that a data leak occurred at the third-party logistics provider ShipMonk, resulting in 67,000 customers in the U.S. losing their personal data. This is the largest breach since Trezor's inception, and over 80,000 users may have been affected by the incident. It has been revealed that customers whose data was compromised placed orders between November 2019 and August 2021, meaning that some of the data leaks could be nearly seven years old.
According to Trezor, 12,742 customers lost complete data, including name, email address, phone number, and shipping address. Additionally, 1,947 customers had a more limited amount of information compromised. "We are extremely disappointed that, despite receiving confirmations, the information was not deleted from their systems,"– the company stated. Trezor emphasized that their own systems were not compromised, and the keys and wallet backups remained secure. Thus, the main threat comes from the acquisition of detailed information about customers, which could lead to phishing emails, fraudulent calls, and counterfeit letters.
Trezor also pointed out potential physical risks for customers who may become targets for criminals. Given that names and shipping addresses have been exposed, fake messages could appear more convincing. In response to the incident, Trezor notified all newly affected customers via email, adding that those who did not receive a notification likely were not affected. Trezor is actively working to improve its security, planning to implement an "anonymous delivery" option in the European Union by September 2026 and in the U.S. by the end of the same year. This measure is intended to help prevent similar incidents in the future.

