Trezor disclosed a breach affecting 67,000 U.S. customers through third-party shipping provider ShipMonk, revealing personal information that the hardware wallet maker believed had been deleted years ago.

The exposed data spans orders placed between November 2019 and August 2021. Compromised records include customer names, email addresses, phone numbers, shipping addresses, and order numbers. ShipMonk handles fulfillment and logistics for Trezor's physical product deliveries.

Trezor emphasized that the breach does not compromise the security of its hardware wallets themselves. The vulnerability existed in ShipMonk's systems, not in Trezor's cryptographic infrastructure or device firmware. Users' cryptocurrency holdings secured by Trezor devices remain unaffected by this incident.

The timing raises questions about data retention practices. Trezor believed this customer information had been purged, yet it remained accessible when ShipMonk's systems were breached. The three-year gap between the order window and the actual breach discovery suggests the data persisted longer than expected in ShipMonk's infrastructure.

This incident joins a growing list of third-party breaches targeting cryptocurrency and fintech companies. Supply chain vulnerabilities in logistics and fulfillment providers expose customers to data theft even when the primary vendor maintains strong security postures. ShipMonk processes orders for multiple clients, meaning a single compromise can cascade across numerous customer bases.

The exposed information falls into the category of personally identifiable information (PII) that threat actors can weaponize for phishing campaigns, social engineering, or identity theft. Attackers know these individuals purchased hardware wallets, offering them pretexts for targeted phishing messages impersonating Trezor support or cryptocurrency exchanges.

Phone numbers combined with email addresses enable SIM swapping attacks or two-factor authentication bypass attempts. Shipping addresses reveal physical locations of individuals known to hold cryptocurrency, creating potential security and safety risks. Order numbers provide additional context for crafting convincing fraudulent communications.

Trezor has not named the threat actor responsible for the ShipMonk breach or released details about how the compromise was discovered. The company advised affected customers to remain vigilant for phishing attempts and to enable additional security measures on email and cryptocurrency exchange accounts.

Third-party breach notifications have become routine across the technology and finance sectors. Companies increasingly rely on external vendors for logistics, payments, customer support, and infrastructure, multiplying potential entry points for attackers. A supplier's weak security practices become a customer's risk.

For hardware wallet users, this incident underscores the distinction between device security and personal privacy. While Trezor wallets remain cryptographically secure, the personal data associated with their purchase creates ongoing exposure. Users should monitor for phishing attempts and consider using privacy-focused email addresses or aliases for future cryptocurrency purchases when possible.

Trezor customers should change passwords on associated email accounts, verify no unauthorized access occurred on cryptocurrency exchanges, and watch for fraudulent communications referencing their orders or account details.