Hardware wallet maker says the expanded breach traces back to a third-party fulfillment partner, not its own systems.
Trezor, one of the largest makers of hardware cryptocurrency wallets, has notified customers of a fresh wave of exposure tied to a data breach. The company said about 67,000 additional US customers are affected, expanding the scope of an incident already under scrutiny.
According to Trezor, the breach originates with ShipMonk, a third-party logistics and fulfillment provider used to ship orders to customers. Trezor itself does not operate its own warehousing for every order, and outsourcing that function to specialized vendors is common practice across e-commerce and hardware technology sectors alike.
The fact that the exposure traces to a fulfillment partner rather than Trezor's core systems is significant for how customers should interpret the risk. Hardware wallets are designed so that private keys and seed phrases never leave the physical device, meaning a shipping-related breach would not typically expose the cryptographic material that secures a user's funds.
However, data collected during the ordering and shipping process, such as names, addresses, and order details, can still be valuable to attackers. Exposed shipping information has repeatedly been used in the crypto industry to craft targeted phishing campaigns or physical-security threats against known wallet owners.
This is not the first time Trezor has had to notify customers about exposure connected to its supply chain. The disclosure of another 67,000 affected US accounts suggests the incident is broader, or took longer to fully map, than initially understood when it first came to light.
Hardware wallet companies have increasingly become targets precisely because their customer lists effectively identify people who hold meaningful amounts of cryptocurrency. That makes any leak of names and addresses more consequential than a typical retail data breach, even when financial credentials or private keys are not involved.
Trezor has not disclosed additional technical detail beyond attributing the breach to ShipMonk and specifying the newly affected customer count. The company's communication focuses on notifying impacted US customers directly rather than issuing a broader public breakdown of the incident's mechanics.
The episode highlights a recurring theme in crypto security: attackers often find it easier to compromise third-party vendors than to break cryptographic protections built into hardware devices themselves. Wallet manufacturers, exchanges, and custody providers all rely on external logistics, marketing, or customer-support tools that sit outside their most hardened security perimeters.
For Trezor, the challenge now is reassuring a security-conscious user base that its core products remain uncompromised, even as it works through the fallout from a partner's data handling. The company's reputation rests heavily on trust in the integrity of its hardware, a trust that supply-chain incidents like this one can strain.
Data breaches at hardware wallet companies tend to have limited direct effect on token prices, since private keys and signing operations are not exposed. The more relevant impact is reputational and behavioral: affected customers may become more cautious about sharing shipping and personal data with wallet vendors, and rival manufacturers could use the incident to emphasize their own supply-chain security practices.
The broader industry implication concerns vendor risk management. As hardware wallet adoption grows alongside institutional and retail custody demand, breaches originating from fulfillment or logistics partners are likely to draw continued attention from security researchers and regulators focused on data protection standards in the crypto sector.
Trezor's latest disclosure underscores how third-party vendors, not just core software or hardware, can become the weak link in crypto security. Customers affected by the expanded breach are being notified directly as the company continues to assess the scope of the ShipMonk-related exposure.
Trezor attributed the expanded breach to ShipMonk, a third-party fulfillment provider it uses to ship customer orders, rather than to its own internal systems.
Trezor's disclosure centers on customer data tied to shipping and orders. Hardware wallets are designed so private keys stay on the device, which limits the risk to funds from this type of breach.
Trezor described this as an expansion, saying an additional 67,000 US customers were found to be affected beyond those already notified in the earlier disclosure.
Customers should watch for official Trezor communications, be cautious of unsolicited messages referencing their order or shipping details, and remain alert to phishing attempts targeting known wallet owners.
Trump Threatens to Halt Trade With Deficit Nations Unless Fed Cuts Rates
Trezor Says Mailing Partner Breach Now Affects Over 80,000 US Customers
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect