Eilmeldung
ITBimbo travolto da un'auto a Cerea: gli è stato amputato un piedeCNTunnel Collapse at Hydropower Project in India Leaves Seven Workers DeadTRHürtgenwald'da Büyük Orman Yangını: 2 Bin Kişinin TahliyesiESIncendio en Niebla (Huelva): más de 31.000 hectáreas afectadas y complejas condiciones para su extinciónTRNATO Sözcüsü Letonya'da Düşürülen İHA ile İlgili Açıklama YaptıINTLUkraine Declares Success in Recapturing 745 km² of Territory in DnipropetrovskRUUS Ambassador to Israel Labels Settlers Besieging Palestinian Homes as "Terrorists"ARاقتصاد سويسري ينمو بقوة في الربع الثاني، وتنصيب الحرب في البحر الأسود على تجارة الغذاء العالمية، وارتفاع عوائد السندات الحقيقية يزيد المخاطر على الأسهم والاقتصادPLZbieranie danych po wycieku w MyDr potrwa jeszcze kilka dniTR2027 İspanya Süper Kupa İstanbul'da düzenlenecekITBimbo travolto da un'auto a Cerea: gli è stato amputato un piedeCNTunnel Collapse at Hydropower Project in India Leaves Seven Workers DeadTRHürtgenwald'da Büyük Orman Yangını: 2 Bin Kişinin TahliyesiESIncendio en Niebla (Huelva): más de 31.000 hectáreas afectadas y complejas condiciones para su extinciónTRNATO Sözcüsü Letonya'da Düşürülen İHA ile İlgili Açıklama YaptıINTLUkraine Declares Success in Recapturing 745 km² of Territory in DnipropetrovskRUUS Ambassador to Israel Labels Settlers Besieging Palestinian Homes as "Terrorists"ARاقتصاد سويسري ينمو بقوة في الربع الثاني، وتنصيب الحرب في البحر الأسود على تجارة الغذاء العالمية، وارتفاع عوائد السندات الحقيقية يزيد المخاطر على الأسهم والاقتصادPLZbieranie danych po wycieku w MyDr potrwa jeszcze kilka dniTR2027 İspanya Süper Kupa İstanbul'da düzenlenecek
Newsgather
ZurückTrezor Customer Data Exposed in ShipMonk Fulfillment Breach
Trezor Customer Data Exposed in ShipMonk Fulfillment Breach
In Entwicklung
CryptoSlatevor 2 StundenTechnik3 Min. Lesezeit

Trezor Customer Data Exposed in ShipMonk Fulfillment Breach

A breach at fulfillment provider ShipMonk exposed personal data and delivery addresses for nearly 13,689 Trezor hardware wallet buyers.

Auf einen Blick

Trezor revealed that a data breach at fulfillment provider ShipMonk exposed personal details and delivery addresses for nearly 13,689 hardware wallet buyers, raising physical security and targeted phishing concerns.

KI-generierte Zusammenfassung

Warum es wichtig ist

Fulfillment provider ShipMonk suffered a data breach exposing personal information of 13,689 Trezor hardware wallet customers.

Schriftgröße

On Aug. 13, Trezor said a breach at the fulfillment provider ShipMonk exposed customer data for about 13,689 hardware wallet buyers, including the delivery addresses of 11,742 people.

The larger group had their names, email addresses, phone numbers, and shipping addresses exposed, while another 1,947 customers had names, cities, and email addresses compromised. ShipMonk handled the information to fulfill and deliver Trezor orders.

Trezor said its own systems, devices, and services were not breached and that customer wallets remain secure. The exposure instead creates a different risk: linking identifiable people and, in most cases, their home addresses to the purchase of a hardware wallet designed to secure crypto holdings.

ShipMonk notified Trezor on Aug. 10 that an unauthorized actor had accessed systems containing customer information, according to the company's Aug. 13 disclosure.

The 11,742 fully exposed records covered orders received between May 10 and Aug. 8. The additional 1,947 records may include older purchases, and Trezor said it was still working with ShipMonk to determine why those records remained available.

Trezor said its fulfillment partners are generally required to delete or anonymize order information within 90 days of delivery, thereby limiting how much recent customer data remains accessible after an order is completed.

Shipping data can turn a digital breach into a physical-security risk

While the exposed records do not provide access to wallets or private keys, they can make phishing and other attacks substantially more targeted.

Trezor warned that scammers could use the information to impersonate the company, banks, or crypto exchanges through convincing emails, phone calls, and letters. An attacker who already knows that a person bought a Trezor device can tailor a message around wallet security, compromised funds, or supposed account problems rather than relying on generic phishing tactics.

The inclusion of delivery addresses raises a more serious concern because it can identify households associated with people who are likely to own crypto.

That does not mean the ShipMonk data has been used for physical attacks. However, previous cases show how customer databases can help criminals identify potential crypto holders before moving from online reconnaissance to real-world targeting.

In a 2025 case unrelated to Trezor, the US Justice Department described an alleged crypto-theft network that used stolen databases to identify victims and included residential burglars targeting hardware-wallet owners.

Chainalysis has also found that the annual value stolen through violent crypto attacks reached a record $58 million in 2025, with another $30 million stolen by the middle of 2026. Home invasions accounted for 37% of recorded incidents this year, up from 26% in 2023.

The blockchain analytics firm said attackers range from criminals who send stolen assets directly to centralized exchanges to more sophisticated groups using laundering infrastructure to obscure the proceeds.

Trezor and crypto executives push tighter privacy measures

Following the recent wave of third-party data breaches affecting crypto service providers, industry leaders are increasingly warning about the risks of overexposed user data.

Helius co-founder and CEO Mert Mumtaz said breaches involving customer information will continue to occur across software providers, arguing that crypto users should reduce the amount of personal information that can be connected across services.

Among his recommendations were using separate email aliases, unique passwords and hardware-based multi-factor authentication rather than SMS. He also urged users to avoid providing unnecessary personal details and, where possible, to have sensitive products delivered to shared or non-residential locations rather than their homes.

Mumtaz also argued that a hardware wallet should not be treated as sufficient protection for substantial holdings, recommending multi-signature setups so compromising a single device or signer cannot expose an entire balance.

Trezor is taking a similar approach on the fulfillment side by trying to reduce the amount of shipping data that remains attached to future purchases.

The company said it plans to introduce Anonymous Delivery in the European Union by September 2026 and in the US by the end of the year. The service would use a dedicated checkout process, locker pickup, neutral packaging, and generic sender details, with shipping identifiers automatically deleted after delivery.

For customers affected by the ShipMonk incident, Trezor advised treating urgent requests for information with suspicion, verifying messages through official channels, and never sharing a wallet backup or entering one into a website.

Worauf zu achten ist

KI-Ausblick — Möglichkeiten, keine Fakten

  • Trezor to introduce Anonymous Delivery in the European Union

    Wahrscheinlich · Innerhalb von Monaten

  • Trezor to launch Anonymous Delivery in the US

    Wahrscheinlich · Innerhalb von Monaten

Offene Fragen

  • Why did older records remain available past the 90-day deletion rule?
  • How did unauthorized actors gain access to ShipMonk's systems?

Verwandte Themen

This article was originally published by CryptoSlate.

Ähnliche Meldungen

Mehr zu diesem Thematrezor