XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Regulation
● Regulation

Trezor Confirms Data Breach Affecting 67,000 US Hardware Wallet Customers

Hardware wallet provider Trezor revealed that 67,000 additional US customers had their personal information compromised through its shipping provider, significantly expanding the initial estimate and raising urgent concerns about potential phishing attacks targeting cryptocurrency holders.

JM
by Jacob Marquez · Regulation Desk
Published September 4, 2026 · 3 min read

Shipping Provider Breach Exposes Vast Customer Data

Hardware wallet manufacturer Trezor announced that a significant data breach at its shipping partner ShipMonk has compromised personal information for 67,000 US customers. The affected users had placed orders between November 2019 and August 2021, with their complete personal details exposed including names, email addresses, phone numbers, shipping addresses, and specific order information. Trezor disclosed the expanded scope through a Friday announcement on X, citing new information provided by ShipMonk regarding customer records that should have been deleted but remained in the company’s systems.

The revised figure represents a substantial increase from Trezor’s initial August estimate of 14,000 affected users. This expansion demonstrates how breaches involving third-party vendors can grow considerably as investigations proceed and additional data retention is discovered. Trezor emphasized that its own systems and security infrastructure did not experience compromise, with the breach originating entirely from ShipMonk’s infrastructure. The company stated that it had previously received written assurances from ShipMonk that customer data would be deleted, but these assurances proved insufficient to prevent the data retention that led to the breach.

Phishing and Social Engineering Threats to Digital Assets

The primary danger to affected customers involves not direct theft of cryptocurrency, but rather sophisticated phishing and social engineering campaigns. With access to customer names, contact information, and purchasing history, attackers can craft convincing communications impersonating Trezor to trick users into revealing sensitive information such as seed phrases—the cryptographic keys that grant complete access to digital asset holdings across different blockchain networks.

Social engineering attacks represent a pervasive threat throughout the broader cryptocurrency industry. According to blockchain security firm Hacken, phishing and social engineering tactics drove the majority of crypto industry losses in the first quarter of 2026, accounting for $306 million of the total $482 million in security losses. These attacks prove particularly effective because they exploit human psychology and trust rather than technical vulnerabilities. In July, a crypto investor lost nearly $1 million after signing a malicious token approval transaction on Ethereum, illustrating how convincing these phishing schemes have become.

Recurring Pattern of Third-Party Security Vulnerabilities

The latest breach compounds previous security incidents involving Trezor and its vendor ecosystem. In January 2024, Trezor disclosed that approximately 66,000 users who had contacted the company’s support team since December 2021 faced phishing risks—a figure strikingly similar in scale to the current exposure. The pattern suggests ongoing challenges within the hardware wallet sector regarding vendor management, data retention policies, and supply chain security.

For cryptocurrency holders storing any digital assets—including those holding XRP and other tokens—the incident reinforces that security extends far beyond the technical architecture of hardware wallets themselves. Every connection point in the supply chain, from manufacturing to shipping to customer support, represents a potential vulnerability. Users should remain vigilant against unsolicited communications claiming to come from wallet providers and should never share seed phrases under any circumstances, regardless of how legitimate such requests might appear. This breach underscores why social engineering remains a dominant attack vector for cryptocurrency losses, making user awareness as critical as technological safeguards in protecting digital assets across the entire ecosystem.

Source: Trezor, via Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Regulation Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.