Trezor announced that a data breach involving its shipping partner ShipMonk has exposed the full personal information of 67,000 U.S. customers. The affected orders were placed between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses and order specifics.
The hardware‑wallet maker said its own systems were not compromised, but the leaked data could be used in phishing or social‑engineering attacks that impersonate Trezor to steal seed phrases and other wallet credentials.
The breach size is larger than the company’s earlier estimates. In August 2025 Trezor had reported that about 14,000 users were impacted, and in January 2024 it warned roughly 66,000 users of phishing risk linked to support interactions. The latest figures bring the total of U.S. customers potentially at risk to 67,000.
Security firm Hacken noted that impersonation scams accounted for $306 million of the $482 million lost to crypto‑related fraud in the first quarter of 2026. The breach underscores the vulnerability of users to non‑technical attacks that do not require exploiting software code.
Trezor blamed ShipMonk for retaining the data despite written assurances that it would be deleted. The company urged affected customers to remain vigilant for suspicious communications and to follow best practices for protecting their wallet recovery information.













