# Trezor's Third-Party Problem: 67,000 Hardware Wallet Owners Just Had Their Home Addresses Leaked


Hardware wallet customers buy Trezor devices precisely because they want their crypto holdings off the internet. What they didn't sign up for was having their home address handed to whoever breached ShipMonk's systems — but that's exactly what happened to 67,000 U.S. customers, Trezor confirmed Friday.


The exposed data runs the full logistics profile: names, email addresses, phone numbers, shipping addresses, and order numbers from purchases made between November 2019 and August 2021. No wallet keys were compromised. The hardware itself is fine. But the people who bought the hardware? Their physical locations are now in someone else's hands.


That's a different kind of problem.


## What ShipMonk Actually Held


ShipMonk is a third-party fulfillment and shipping platform. Trezor, like many e-commerce operations, used it to handle logistics — warehousing, packing, shipping orders to customers. That workflow requires ShipMonk to hold exactly the kind of data that just got exposed: real names tied to real addresses tied to specific product purchases.


For most companies, a fulfillment breach like this means spam, phishing attempts, maybe some fraud. For a company whose entire customer base consists of people who demonstrably own cryptocurrency hardware, it means something more specific.


A name and address attached to a Trezor order isn't just a marketing lead. It's a signal. It tells anyone paying attention that this person took enough interest in self-custody crypto to spend money on physical security hardware. That's not a subtle demographic. Threat actors targeting crypto holders for physical coercion — what the security community calls "wrench attacks," a blunt phrase for a blunt threat — start exactly with this kind of list.


## The Deletion Problem


There's a line in Trezor's disclosure that deserves more scrutiny than it will likely receive: the company said the data was supposed to have been deleted.


This is the fourth data incident Trezor has disclosed involving third-party vendors. In 2022, a MailChimp breach exposed Trezor customer email addresses. Also that year, a Typeform breach hit newsletter subscribers. Earlier this year, Trezor disclosed another vendor incident involving tens of thousands of support ticket contacts. Now ShipMonk, with data that allegedly should no longer have existed.


The pattern here isn't one rogue vendor. It's a systemic failure to close the loop on data retention. Companies integrate tools, ship product, and don't follow up to confirm that the contractual promise — "delete our customer records after X days" — was actually executed. ShipMonk apparently retained Trezor customer data for years after it should have been purged. The exact timeline of the breach itself hasn't been made public, but the exposure window represents orders placed between late 2019 and mid-2021. Five-plus years of data that shouldn't have been there.


For any company handling sensitive customer relationships, this is the lesson that keeps not being learned: vendor data retention promises aren't self-enforcing.


## What the Hardware Wallet Community Should Actually Worry About


The immediate threat isn't someone cracking a Trezor device using a leaked shipping address. Trezor's hardware security model holds here. The real exposure is social engineering at scale.


These 67,000 records are a ready-made targeting list. Expect:


  • Spear phishing that references real order details to establish false legitimacy ("Your Trezor order from October 2020 requires action...")
  • SMS-based attacks using the leaked phone numbers to impersonate Trezor support
  • Physical mail scams sent to the leaked addresses, potentially including fake firmware update USBs — a vector Trezor has explicitly warned about before

  • The order number exposure is underappreciated here. With an order number, an attacker can construct a highly credible phishing pretext. Most people don't remember the specifics of a 2020 purchase. When an email references a real order number and a correct shipping address, it feels authentic. It isn't.


    ## Third-Party Risk in the Crypto Stack


    Hardware wallet companies occupy a strange position in the security landscape. They build products specifically for people who distrust custodial services. Their customers are, almost by definition, more security-conscious than average. Yet the logistics layer underneath — the fulfillment centers, the email platforms, the support ticket tools — operates on standard e-commerce risk assumptions.


    Those assumptions don't hold when your customer base is high-value crypto holders.


    Trezor's repeat vendor breach history suggests the company hasn't yet designed its vendor relationships to match its customer threat model. That gap is the real vulnerability, and no firmware update fixes it. It requires auditing which vendors hold customer data, enforcing deletion timelines technically rather than contractually, and minimizing what third parties receive in the first place.


    Competitor Ledger learned this the hard way in 2020, when a direct database breach exposed over a million customer records including home addresses. The fallout included a sustained harassment campaign against customers, doxxing, and credible physical threats. Ledger's breach was larger, but the risk profile for affected Trezor customers is functionally similar.


    ## For Those Affected


    Trezor says it will notify affected U.S. customers directly. If you purchased a Trezor device between November 2019 and August 2021 and haven't received notification, watch for it — and treat any inbound contact claiming to be from Trezor with heightened skepticism regardless.


    Specific steps worth taking now:


  • Don't act on any communication that references your order history without independently verifying it through Trezor's official website
  • Enable two-factor authentication on any account tied to the exposed email address
  • Be alert to phone calls or texts from numbers claiming to be Trezor or ShipMonk support — neither company has a reason to call you
  • Your seed phrase is still yours. The breach doesn't touch it. But anyone who asks for it — regardless of what they claim to know about your order — is attempting fraud

  • ---


    ## HackWire Analysis


    The ShipMonk breach is being reported primarily as a "no wallet security impact" story, and technically that's accurate. But framing it that way buries the genuine risk.


    Trezor now has four disclosed third-party vendor incidents on the board. The 2022 MailChimp breach. The 2022 Typeform breach. An earlier 2024 support vendor incident affecting 66,000 contacts. And now ShipMonk, with data that should have been deleted years ago. At some point, the pattern stops being bad luck and starts being a procurement problem.


    The crypto-specific threat model makes this worse than it would be for most consumer hardware companies. When Ring cameras get breached, you worry about people watching your doorbell footage. When a hardware wallet manufacturer's shipping data gets breached, the people with your home address know you own cryptocurrency. That knowledge has a market. The Ledger breach of 2020 produced years of documented harassment, threats, and social engineering attempts targeting real customers by name at real addresses.


    What's missing from most coverage here is the vendor governance dimension. The data retention failure — ShipMonk allegedly keeping records that were supposed to be deleted — is a controls problem, not just a security incident. Trezor's data processor agreement with ShipMonk presumably included deletion requirements. The fact that 2019-2021 data was still sitting in ShipMonk's systems suggests either the deletion was never requested, never confirmed, or never actually performed. None of those scenarios reflects a mature vendor security program.


    Hardware wallet companies are selling trust. Every breach of a vendor holding their customer data costs real trust, even when the hardware itself is uncompromised. Trezor's core product is fine. Its third-party governance, based on the evidence, clearly isn't.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)