CRYPTO

Trezor says 14,000 customers' data leaked by shipper

A shipping partner exposed customer information for roughly 14,000 Trezor users, but the hardware wallets and private keys stored on them remain secure.

Trezor, which makes hardware wallets, said that ShipMonk, the company that handles its deliveries, exposed customer data for around 14,000 users. The exposure happened through ShipMonk's systems, not Trezor's own. Trezor said the leaked information could include names, addresses, phone numbers and email addresses. The company warned customers to watch for phishing attempts, which are fake messages designed to trick people into revealing passwords or other sensitive details.

A hardware wallet is a physical device that stores the private keys needed to access and move cryptocurrency. Think of a private key as the master password that controls a crypto account. It lives offline on the device itself, never exposed to the internet. Even if someone steals a Trezor device, they cannot access the funds without the PIN code set by the owner. The wallet generates a backup recovery phrase (a list of words) that can restore access if the device is lost or broken.

Because the breach happened at a shipping partner, not at Trezor, the devices themselves were never compromised. This means the private keys and recovery phrases stored on Trezor wallets remain secret. Customer funds are protected. The risk is not to the crypto holdings but to personal information that could be used to target Trezor owners with convincing phishing emails or messages.

For Trezor owners, the practical concern is heightened. Attackers now know they hold cryptocurrency, and they have contact information to start with. An attacker could send a fake email pretending to be from Trezor, asking the user to verify their account or update payment details. The company advised users to ignore unsolicited messages and never click links in them. Legitimate Trezor communications come through official channels like the company's website or support ticketing system.

Trezor did not say how the breach was discovered or when it occurred. The company also did not detail what security measures failed at ShipMonk or whether ShipMonk has notified other customers whose data may have been exposed through the same incident. Both questions remain unanswered.

First reported by Cointelegraph - Read the original report.

MORE IN WEB3

← ALL ARTICLES & NEWS