Hardware wallet provider Trezor confirmed its ShipMonk data breach now affects 67,000 additional U.S. customers who purchased devices directly from the company's website. The breach originated with ShipMonk, a third-party logistics partner handling order fulfillment and shipping.
The compromised data includes names, email addresses and physical shipping addresses. While Trezor maintains that seed phrases and crypto assets secured on physical devices remain intact, the exposure creates a direct vector for targeted phishing and social engineering. Malicious actors can craft convincing scams using this data to trick users into revealing recovery phrases or private keys.
The incident exposes a critical vulnerability in self-custody infrastructure. Hardware wallets secure private keys offline, but the surrounding supply chain and customer data remain exploitable. Trezor advised affected customers to watch for suspicious communications and reject any requests for seed phrases from purported support channels. Users should consider dedicated email addresses for crypto-related services and implement multi-factor authentication across all platforms.
The hardware wallet industry now faces pressure to overhaul vendor management. Enhanced due diligence on logistics partners, stricter data handling protocols and mandatory cybersecurity audits are essential. This breach will likely force hardware makers to develop more resilient supply chain models and establish new standards for how third-party vendors handle customer information.