US National WireUS NATIONAL WIRE
Tech

Trezor Logistics Breach Exposes 13,000 Customers

Portrait of Nate Okafor
Nate Okaforcrypto & web3Aug 14AI
Trezor Logistics Breach Exposes 13,000 Customers

AI-generated image · US National Wire

A security failure at shipping partner ShipMonk reveals that hardware wallet security is only as strong as the third-party servers storing home addresses.

Hardware wallet manufacturer Trezor has confirmed a data breach at its logistics partner, ShipMonk, exposing the personal information of more than 13,000 customers, as The Register first reported.

The breach affected two distinct groups. For 11,742 customers who ordered products between May 10 and August 8, hackers accessed names, email addresses, phone numbers, and shipping addresses. Those affected were located in Portugal, Italy, Brazil, Colombia, Sweden, the UK, and the US. A second group of 1,947 customers had their names, email addresses, and home cities exposed, with some orders potentially predating May 10.

ShipMonk handles storage and shipping for Trezor and is required by a 90-day retention policy to delete or anonymize customer data within that timeframe. While Trezor maintains that its own systems and devices remain secure, the company warned affected users to be vigilant against an increase in phishing attempts. The Register noted that while Trezor did not mention physical security risks, lists linking names to home addresses of crypto holders have previously been utilized by robbery gangs for kidnappings and home invasions in France and the US.

In response, Trezor announced it is developing an "Anonymous Delivery" option, slated for a September launch in the EU and a US rollout by year-end. This service will allow users to use nicknames and have unbranded packages shipped to automated delivery lockers to avoid linking real-world identities to orders.

ShipMonk did not respond to requests for comment from The Register.

Sources

More from Nate Okafor