What hardware wallet makers fear most has never been a cracked private key—it's someone knowing where you live, your phone number, and where your last online order was shipped. Trezor confirmed Thursday that its logistics partner ShipMonk's systems were breached by hackers, leaking sensitive personal data of nearly 14,000 customers, with victims spanning the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Breaking down the scale of the leak: 11,742 customers had their names, emails, phone numbers, and shipping addresses fully exposed; another 1,947 people had their names, city of residence, and emails leaked. Trezor posted on X saying "we have to announce heavy news," and has already notified all affected users via email—if you didn't receive one, your personal data is safe. Consumers who purchased through Amazon are unaffected, as the platform uses a separate, independent logistics partner.
Trezor emphasized that its own internal systems were not breached, and the device-side cryptographic protections have "never been remotely broken" to date—no cryptocurrency itself was stolen. But that's exactly where the problem lies: once addresses and phone numbers are leaked, scammers don't need to crack anything—they can simply mail a malware-laden fake cold wallet to your door using the shipping data, or impersonate a bank, exchange, or even Trezor itself over the phone to demand passwords and private keys. After Ledger leaked nearly 300,000 users' data in 2020, fake cold wallet mail scams emerged the following year, using almost the exact same playbook.
This isn't the first time Trezor has been tripped up by a third party. Parent company Satoshi Labs suffered a customer service system hack affecting 66,000 people this past January, and over 100,000 customers' data was exposed in April 2022; but this marks the first time in the company's 13-year history that phone numbers and shipping addresses have leaked together. The device being fine doesn't mean the person holding it is fine—blockchain security firm Certik reports that face-to-face coercion robbery losses alone hit $124 million in the first half of this year.
Trezor currently states it has found no evidence that the leaked personal data has been made public or sold, nor any reports of related scams—but once shipping addresses are out, the risk typically doesn't fade along with the news cycle.






