Trezor, a leading provider of crypto hardware wallets, has acknowledged a much larger exposure of customer data. Its logistics partner found thousands more records in compromised systems. The update adds 67,000 customers from the United States, raising serious concerns about privacy, phishing, impersonation, and physical targeting risks for users.
According to the disclosure, the exposed records reportedly included names, email addresses, phone numbers, shipping addresses, and order information linked to their purchases.
Trezor Expands Breach Disclosure
The latest announcement follows Trezor’s earlier disclosure that a security incident at ShipMonk exposed customer information associated with hardware-wallet orders. The initial investigation identified 11,742 customers whose personal information had been accessed, prompting warnings about phishing and targeted scams.
Further investigation by ShipMonk has now uncovered records belonging to another 67,000 customers in the U.S, considerably expanding the incident’s scope. The newly affected records relate to orders placed over nearly two years, from November 2019 through August 2021. This has raised concerns about the long-term retention of sensitive customer information.
The company said that the breach did not provide attackers with access to customers’ devices, recovery seeds, or crypto assets. However, knowing who purchased a hardware wallet can give criminals valuable information for impersonation, phishing, and other targeted attacks.
Trezor has urged affected users to treat unsolicited messages with caution, particularly communications requesting passwords, recovery phrases, payments, or other sensitive information.
Crypto Data Breaches Continue to Increase
The expanded Trezor disclosure adds to a growing history of breaches involving crypto companies, where compromised customer information has sometimes created risks long after the original incident. One such notable example involved Coinkite, a Canadian bitcoin hardware wallet company, which warned its users after it suffered a security vulnerability.
The issue reportedly affected some of its Coldcard Mk3 devices that generated wallet seeds using a vulnerable process. The breach, which initially began modestly, was later linked to the theft of over $100 million. The funds were swept from 500 single-signature addresses, making it one of the largest known losses related to hardware wallets.
Additionally, hardware-wallet manufacturer Ledger disclosed a major e-commerce database breach affecting customer information, including more than one million email addresses and additional personal details. The incident subsequently fueled phishing campaigns targeting Ledger users.
These incidents highlight a broader weakness within the cryptocurrency industry: customer data can become a valuable target independently of blockchain assets. The Trezor incident is particularly significant because the exposure occurred through a third-party logistics provider rather than the hardware wallet itself.












