Trezor says the fallout from a data exposure tied to its shipping partner is wider than it first indicated. In a Friday post on X, the hardware wallet provider updated the number of potentially impacted US customers, saying an additional 67,000 people may have had their full order details exposed.
The company stressed that its own systems were not breached. However, it warned that exposed informationโsuch as names, email addresses, shipping addresses, and order specificsโcould still be used by criminals to target victims with convincing phishing attempts. The goal, Trezor said, would be to trick users into revealing seed phrases, the credentials that control funds stored in hardware wallets.
Key takeaways
- Trezorโs latest update suggests the shipping-related exposure may involve an additional 67,000 US customers.
- Company systems were not compromised, but order records were reportedly not deleted by the shipping provider for certain customer orders.
- Trezor believes the main risk is impersonation-based phishing aimed at extracting wallet seed phrases.
- Earlier estimates put the exposure at 14,000 users, indicating the scope expanded after further information from ShipMonk.
- Investors and wallet users should treat any โTrezor supportโ messages as suspicious until verified through official channels.
Updated scope: more US customers at potential risk
Trezorโs Friday X update referenced a new report from its shipping provider, ShipMonk. The hardware wallet firm said the affected population includes US customers who placed orders between November 2019 and August 2021. According to Trezor, these customers may have had their complete details exposed, including identity and contact information, delivery addresses, and order-specific data.
This revision matters because it changes the number of people who may need to take additional precautions. Trezor initially estimated in August that only 14,000 users had their data exposed through ShipMonk. The new figure indicates that the problemโs reach was underestimated at the timeโor that additional affected orders were identified as the investigation progressed.
What was exposedโand why it can still be dangerous
Trezor said the exposed records included the full set of personal and purchase information that bad actors typically need to make impersonation scams credible. That includes usersโ names, email addresses, shipping addresses, and order specifics.
Even though Trezor said its systems were not breached, the company argued that the exposed information could be used to carry out more targeted social engineering. The concern is not just general spam or list-based fraud; it is the possibility of messages that appear to come from Trezor, designed to pressure recipients into revealing their seed phrases or otherwise compromising their wallets.
In other words, attackers may not need technical access to a wallet to cause loss. If a scam convincingly imitates the legitimate support processโor references a customerโs order to establish trustโvictims may be more likely to comply.
Why impersonation scams keep costing the industry
Security research underscores how effective phishing and related social engineering can be in crypto. In the first quarter, blockchain security firm Hacken reported that social engineering and phishing drove most of the industryโs losses. According to Hacken, these attacks accounted for $306 million of $482 million total losses in that period.
The mechanics are often straightforward: fraudsters send messages that mimic trusted brands, then guide victims toward actions that compromise accounts or keys. Trezorโs warning fits that pattern, targeting the most sensitive asset in self-custody setupsโthe seed phrase.
Earlier coverage also highlighted how phishing can lead to direct on-chain loss. In July, a crypto investor reportedly lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum.
Trezorโs prior communications and what remains unclear
While the latest update expands the number of potentially impacted customers, it aligns with earlier disclosures that Trezor had been tracking risk tied to contact and support interactions. In January 2024, Trezor reported that about 66,000 users were at risk of phishing attacks if they had contacted the companyโs support team since December 2021.
That earlier statement focused on a different slice of riskโsupport-related contactโwhereas the new update centers on order-related data tied to shipping. Taken together, the communications suggest that Trezorโs threat model evolved as more information became available and as different parts of the customer journey were assessed.
One important point remains: Trezor continues to state that its systems were not compromised. The danger appears to come from information that may have been retained or not deleted by the shipping provider for certain orders, enabling third parties to craft more personalized scams.
What readers should watch next is whether Trezor provides further detail on mitigation stepsโparticularly how it plans to reach potentially exposed customersโand whether additional countries or time ranges are affected. The companyโs current update is limited to additional 67,000 US customers in the November 2019 to August 2021 window, but future revisions are possible if ShipMonkโs findings expand again.
For now, the practical takeaway for hardware wallet holders is to be especially cautious of any outreach that claims to be from Trezor, especially if it references an order. Verify through official channels before taking any action, and treat requests involving seed phrases as an immediate red flag.






