Loading market data...

Trezor Data Breach at Shipping Partner Exposes 13,700 Customers' Addresses

Trezor Data Breach at Shipping Partner Exposes 13,700 Customers' Addresses

Trezor disclosed a data breach at its shipping partner ShipMonk on August 13, exposing personal information of roughly 13,700 recent customers. Names, phone numbers, and home addresses were among the data leaked. The company warned that the information could fuel more sophisticated phishing attempts.

What ShipMonk exposed

The breach hit customers who ordered Trezor devices recently. ShipMonk handles fulfillment for the hardware wallet maker. The leaked data includes names, phone numbers, and home addresses. Trezor said the exposure could lead to more targeted phishing through email, phone calls, or letters. The company urged users never to enter their wallet backup online or share it with anyone.

CZ: software wallets dodge the shipping risk

Binance founder Changpeng Zhao responded to the news by pointing to an advantage of software self-custody wallets. They don't require shipping a physical device that ties identity to a home address. CZ said hardware wallets are "generally true" to be more secure in a few specific aspects, but this incident shows a different risk profile. He stressed he's not saying hardware wallets are bad. He cited Binance Web3 Wallet and Trust Wallet as examples of software wallets that avoid the shipping risk.

The threat beyond phishing

Security researchers warn the leaked addresses could be used for more than phishing. NaoX Protocol said exposed addresses could give attackers a list of verified crypto holders worth targeting in person. Bitcoin security executive Nick Neuman warned the data could lead to targeted social engineering and potentially wrench attacks. That's a physical threat where attackers force victims to hand over funds.

Trezor's advice, and a familiar pattern

Trezor told customers to be on guard for phishing attempts via email, phone, or even letters. The company reiterated that wallet backups should never be entered online or shared. This isn't Trezor's first breach. In January 2024, a third-party support vendor exposed contact details for around 66,000 users.

The wider hardware wallet debate

The incident adds to an ongoing argument about hardware versus software wallets. In mid-July, on-chain investigator ZachXBT called hardware wallets "complete garbage" on Telegram, arguing a spare phone used only for signing transactions could work better. Separately, Galaxy Research linked more than $100 million in stolen Bitcoin to a flaw in older Coldcard firmware that generated wallet seeds with weaker randomness than intended. Coinkite has patched the flaw but cannot fix seeds already generated, advising holders of Mk3 through Q models to move funds.