80,000 Hardware Wallet Owners Exposed: Why Your Device Security Isn't Enough
More than 80,000 Trezor hardware wallet customers had their personal information exposed through a breach at the company's logistics provider, ShipMonk, highlighting a critical gap in on-chain security that goes beyond protecting private keys. The newly discovered records, which date from November 2019 through August 2021, included names, email addresses, phone numbers, shipping addresses and order numbers for 67,000 additional U.S. customers. This discovery came after Trezor initially disclosed a smaller breach affecting approximately 13,689 customers in August 2026, only to later uncover that older data had persisted in ShipMonk's systems despite repeated deletion requests.
What Makes This Breach Different From a Typical Data Leak?
While Trezor confirmed that its own systems, private keys, wallet backups and device secrets were not compromised, the exposure of customer identity and location data creates a uniquely dangerous threat profile. The leaked information can help attackers identify hardware wallet owners and craft highly personalized scams that appear legitimate because they reference real order details and shipping addresses. Trezor warned affected users to expect fake emails, fraudulent calls and physical letters, and also highlighted possible physical-security threats to their homes.
This incident illustrates a principle that security researchers have increasingly emphasized: self-custody of cryptocurrency does not eliminate risk, but rather shifts it to different parts of the security chain. Security firm TRM Labs has argued that while the wallet itself may remain protected, shipping records expose the owner's identity, contact details and home address, creating new attack vectors that traditional hardware wallet security was never designed to address.
How Did This Data Persist Despite Deletion Requests?
Trezor said it repeatedly requested that ShipMonk delete customer records and received written assurances that the data had been removed under its contract and data policy. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems," Trezor stated. The company initially believed it had a 90-day retention policy in place, which would have limited exposure to recent orders. However, the discovery of records spanning nearly two years revealed that ShipMonk had retained far older customer data than expected.
Trezor
The timeline of the breach shows how security gaps can compound over time. The incident was first disclosed on August 13, 2026, when Trezor said ShipMonk's breach affected about 13,689 customers. The later discovery of records dating back to 2019 demonstrates that older customer data remained in ShipMonk's systems long after Trezor believed it had been purged.
Ways to Understand the Full Scope of Hardware Wallet Security
- Device-Level Security: Hardware wallets like Trezor protect private keys and wallet backups through isolated hardware, but this represents only one layer of a multi-part security ecosystem that includes shipping records, customer databases, and personal identity information.
- Third-Party Risk Exposure: Even when a company's own systems remain secure, data held by logistics partners, payment processors, and other service providers can expose sensitive information about wallet owners, including their home addresses and purchase history.
- Social Engineering Vulnerability: Leaked customer data enables attackers to craft highly targeted phishing campaigns, fraudulent calls and physical threats that reference real order details, making scams appear far more credible than generic mass-market attacks.
- Retention Policy Enforcement: Data deletion agreements between companies and their service providers require ongoing verification and auditing to ensure compliance, as written assurances alone do not guarantee that records have actually been removed from all systems.
The Trezor breach underscores a broader challenge in on-chain security: protecting cryptocurrency assets requires attention to operational security practices that extend well beyond smart contract audits and hardware device design. Customers who believed their assets were secure because they used a hardware wallet discovered that their physical security and privacy had been compromised through a third-party vendor relationship they may not have fully understood.
All newly affected customers have been notified by email, and Trezor has advised users to remain vigilant against targeted social engineering attempts. The incident serves as a reminder that comprehensive security in the crypto ecosystem requires not only technical safeguards but also careful vendor management, data retention policies and ongoing verification that those policies are actually being followed in practice.