×

Trezor Reports Third-Party Breach Affecting 14,000 Customers

Trezor Reports Third-Party Breach Affecting 14,000 Customers

Trezor has notified nearly 14,000 customers after its fulfillment partner, ShipMonk, suffered a security breach that exposed sensitive customer information.

The incident marks the first known Trezor breach to expose customers’ shipping addresses.

The company said information belonging to 11,742 customers, including names, email addresses, phone numbers and shipping addresses, was compromised. Another 1,947 customers had their names, cities and email addresses exposed. The affected users are located across the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal.

Trezor revealed the incident Thursday, explaining that one of its shipping providers had experienced unauthorized access to systems containing order information.

The breach comes as cybersecurity incidents continue to increase globally. SentinelOne reported that data breaches are up 17% from 2025, with an average of 2,090 attacks recorded worldwide each week. The firm also estimated that breaches have been rising by about 3% month over month since January.

Trezor said it emailed all customers whose information was affected and confirmed that customers who did not receive an alert were not impacted. The company told CoinDesk that it has not seen evidence so far that the exposed data has been published, distributed or sold.

It also said there are no known scams or hacking attempts connected to the incident at this time. Customers who bought Trezor products through Amazon were unaffected because those orders are handled by another fulfillment provider.

Crypto Assets Were Not Directly Exposed

Trezor said its own systems were not compromised and that its hardware wallets remain secure. The breach did not provide attackers with direct access to users’ crypto holdings.

The main threat is the potential for phishing and social-engineering attacks. Attackers could use the leaked information to pose as Trezor representatives, banks or crypto exchanges and contact customers through email, phone calls or physical mail.

Stolen personal information can remain valuable long after the original breach. Criminals may reuse or sell shipping records for future fraud, phishing campaigns and targeted attacks.

Leaked home addresses can also create physical security risks. In previous cases, criminals have used such information to demand ransoms of $700 to $1,000 or send fake hardware devices directly to victims. Companies can also face significant legal, remediation and reputational costs following major data leaks.

The threat to crypto holders extends beyond online attacks. CertiK reported that physical coercion incidents involving crypto users reached $124 million during the first half of the year, although the attacks were not necessarily connected to data breaches. DeepStrike estimates that data breaches result in tens of billions of dollars in losses worldwide each year.

Previous Trezor Security Incidents

Trezor said this is the first incident in its 13-year history involving the exposure of customer phone numbers and shipping addresses.

The company has experienced other third-party security incidents. Satoshi Labs, which operates Trezor, reported a breach of an external support portal in January 2024 that affected 66,000 people. A separate incident in April 2022 exposed information linked to 106,856 Trezor customers.

Trezor maintains that its internal firmware and on-device cryptographic security have never been remotely compromised to steal customer funds.

Other hardware wallet providers have faced similar problems. Ledger experienced a January data breach involving its third-party e-commerce provider, Global-e. The company also suffered a major breach in 2020 that affected nearly 300,000 users. In 2021, scammers exploited information from that breach in a phishing campaign that involved sending counterfeit Ledger devices to victims.

Share this content:

Copyright © 2025 CoinsNewz