Exposed Home Addresses Of 81,000 Trezor Customers Raise Physical Security Concerns For Crypto Hardware Owners

Trezor, a leading manufacturer of cryptocurrency hardware wallets, has substantially revised the scope of a data breach involving its former shipping partner, ShipMonk.
The company disclosed that an additional 67,000 U.S. customers who placed orders between November 2019 and August 2021 had their personal information compromised, dramatically expanding the approximately 14,000 individuals initially reported affected on August 13.
The updated disclosure raises the total number of impacted customers to roughly 81,000. While the initial breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers, along with partial data for another 1,947, the newly identified records contain comprehensive personal details including names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor emphasized that its own infrastructure was not breached and that its hardware wallets remain fully secure. All affected individuals have been contacted directly via email, and the company noted that customers who did not receive a notification are not impacted by this latest disclosure.
Contractual Breaches and Physical Security Implications
The incident exposes critical failures in third-party data management and contractual compliance. Throughout its engagement with ShipMonk, Trezor repeatedly requested the deletion of customer information and obtained written assurances that the data had been removed in accordance with their contractual obligations and data protection policies.
Trezor maintained a strict policy requiring fulfillment partners to delete or anonymize order data within 90 days of delivery. The company expressed profound disappointment that these commitments were not honored, leaving sensitive information retained in ShipMonk’s systems for years despite explicit written confirmation of its destruction.
Beyond conventional concerns of identity theft and digital fraud, the breach underscores the distinctive physical security risks faced by cryptocurrency hardware wallet owners. The exposure of residential addresses linked to known purchases of devices designed to secure high-value digital assets creates vulnerabilities that extend well beyond typical phishing campaigns.
Trezor warned affected customers to exercise heightened vigilance regarding scam emails, fraudulent telephone calls, and deceptive correspondence, while explicitly acknowledging potential physical security implications for individuals whose home addresses are now publicly associated with cryptocurrency ownership.
The situation closely parallels the 2020 Ledger data breach, which exposed information belonging to over 270,000 customers and resulted in persistent social engineering attacks, scam phone calls, and physical threats that continued for years after the initial disclosure. The recurrence of such incidents highlights the urgent need for stronger oversight of fulfillment partners in the cryptocurrency hardware sector.
In response, Trezor announced it is actively developing anonymous delivery options to protect customer information in future transactions. The company also reinforced its fundamental security guidance, advising users never to share wallet recovery phrases or enter them into any website under any circumstances.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



