Trezor Customers Targeted by Phishing Scams Following Shipping Partner Breach
An additional 67,000 users of SatoshiLabs, the developer of hardware cryptocurrency wallet Trezor, are now vulnerable to targeted phishing campaigns after sensitive personal information was compromised.
Breach Details
The breach involved customer names, contact details, and shipping addresses, which could enable malicious actors to execute sophisticated social engineering attacks, including fraudulent phone calls, deceptive mail, and physical security threats.
The Czech-based company confirmed the incident stemmed from a data exposure at ShipMonk, the logistics provider responsible for distributing Trezor devices. The breach occurred when unauthorized entities accessed ShipMonk’s systems, which stored customer data for orders processed between May 10 and August 8, 2026.
ShipMonk later disclosed that the intrusion exploited a previously unknown vulnerability in the Metabase Cloud SaaS platform. Despite contractual obligations requiring third-party vendors to delete or anonymize customer data after 90 days, ShipMonk allegedly failed to comply for shipments to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
This oversight affected 3,889 individuals initially, with subsequent revelations indicating that 67,000 additional U.S.-based customers from November 2019 to August 2021 were also impacted.
Company Response
SatoshiLabs emphasized that its internal systems remained secure and that user devices were not compromised. The company reiterated its disappointment over ShipMonk’s failure to adhere to data retention policies, stating, “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
“We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected.”
The firm is also developing new security measures, including anonymous delivery options, locker pickup services, neutral packaging, and automatic removal of shipping identifiers post-delivery. Customers are encouraged to use alternative addresses, cryptocurrency payments, or disposable payment methods to obscure their purchases.
Mitigation and Risks
SatoshiLabs has notified affected customers and advised vigilance against suspicious communications. The breach has raised concerns about physical security threats, as some users reported receiving phishing attempts via mail containing malicious QR codes.
This marks the first instance since Trezor’s founding in 2013 where customer phone numbers and shipping addresses were exposed.
Blockchain analytics firm Chainalysis reported a significant rise in violent crimes targeting cryptocurrency holders, with over $30 million stolen this year alone. Analysts warn that if current trends persist, 2026 could surpass 2025’s $58 million in crypto-related violent attacks.
Security experts recommend avoiding public disclosure of cryptocurrency holdings, utilizing decoy wallets, and implementing multi-signature authentication to reduce exposure.
Industry Implications
The incident underscores the growing risks associated with third-party vendor relationships in the cryptocurrency industry. As adoption of digital assets continues to expand, the potential for criminal exploitation of personal data remains a critical concern for both providers and users.
Key Takeaways
- 67,000 U.S.-based customers impacted by data exposure
- ShipMonk failed to delete data as per contractual obligations
- Phishing risks include mail, phone calls, and physical threats
- Blockchain analytics show rising crypto-related violent crimes
