Cryptocurrency wallet giant Trezor has revealed that a massive data leak at its logistics partner, ShipMonk, has now affected 81,000 customers. The breach exposes sensitive personal data, raising severe phishing risks for crypto holders.

  • Total affected users increased from 14,000 to 81,000 after a second wave of discoveries.
  • The breach occurred via a third-party logistics provider, ShipMonk, not Trezor's internal systems.
  • Exposed data includes full names, shipping addresses, emails, and phone numbers.
  • The attack is linked to a Metabase SQL injection vulnerability exploited by the ShinyHunters gang.

In a staggering escalation of a security crisis, Trezor, the renowned cryptocurrency hardware wallet manufacturer, has announced that the impact of a recent data breach has surged to 81,000 customers. The company disclosed that an initial leak of 14,000 users was merely the tip of the iceberg, with an additional 67,000 U.S.-based customers now confirmed as victims of a failure at their shipping and logistics partner, ShipMonk.

The situation has turned into a contractual nightmare for Trezor. According to the company, ShipMonk had repeatedly provided written assurances that sensitive customer data had been deleted in accordance with their data policy and contractual obligations. However, it was revealed that ShipMonk failed to purge this data, leaving records of customers who ordered between November 2019 and August 2021 vulnerable to exploitation.

Why This Matters

BozokMedia analysis shows that this incident highlights a critical weakness in the modern supply chain: Third-Party Risk Management (TPRM). While Trezor's own hardware and internal systems remain secure, the 'peripheral' data held by logistics partners becomes a goldmine for hackers. In the crypto world, where anonymity is prized, the exposure of a physical shipping address linked to a hardware wallet purchase can lead to targeted social engineering or even physical security threats.

The shift from technical hacking of wallets to the exploitation of logistics metadata represents a dangerous evolution in targeting high-net-worth crypto holders.

Investigation into the root cause reveals that the attackers exploited a critical SQL injection zero-day vulnerability in Metabase, a third-party analytics platform used by ShipMonk. This allowed the threat actors to gain administrator access and siphon off massive amounts of data. Further reports indicate that the notorious ShinyHunters extortion gang has been sending demands to ShipMonk, suggesting the data is being held for ransom.

This is not the first time Trezor has faced such a crisis. In January 2024, a separate breach of a third-party support portal exposed 66,000 users, which subsequently led to aggressive phishing campaigns targeting the 24-word recovery seeds of users' wallets.

strong{Did You Know?:} Hardware wallets are designed to keep private keys offline, but 'metadata' (like your home address) is often stored in online databases by shipping companies, creating a separate security vulnerability.
Breach Event Affected Users Source of Leak Data Exposed
August 2026 Breach 81,000 ShipMonk (Logistics) Name, Address, Phone, Email
January 2024 Breach 66,000 Support Portal Usernames, Emails

Frequently Asked Questions

Q1: Are my funds on the Trezor device safe?
Yes, Trezor has confirmed that its internal systems were not compromised and the devices themselves remain secure. Your private keys are not leaked.

Q2: What should I do if my data was leaked?
Be extremely vigilant against phishing emails, fraudulent calls, or letters. Never share your 24-word recovery seed with anyone, regardless of who they claim to be.