pull down to refresh

Ouch:

The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).
ShipMonk, one of Trezor’s shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses. Trezor devices are secure, but affected customers could experience an increase in phishing attempts. This data breach can potentially affect new customers who received an order from the following countries: US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between 10th of May and 8th of August 2026. If you are unsure whether you were affected, please check your email inbox for a message from help@trezor.io
ShipMonk is the logistics partner that stores our products and ships orders to customers in the US, UK and several other countries. To deliver a parcel, they need your name, shipping address, phone number (required by delivery companies), and email address. That is the only reason they hold any of your data, and under our policy they must delete or anonymize it 90 days after delivery.

I'm surprised, given the high-risk nature of having shipping information leaked, hardware wallet companies don't just keep the logistics in house (at least the point of handing the package off to the actual shipper).

There's an X post as well:

The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email. If you did not receive an email from help@trezor.io then you are not affected by this data breach.
reply

Ah, thanks for calling that last bit out!

reply

i can’t zap because was fixed, comment again for zap

315 sats \ 1 reply \ @nout 13 Aug

One thing that surprised me were the numbers. 12k new users in 3 months, that's ~50k per year. That was higher than I expect.

reply
105 sats \ 0 replies \ @Diego 13 Aug

maybe be higher than usual because of cold card incident?

reply

Logistics in-house is easier said than done at global scale, but at this point hardware wallet vendors must mandate zero-retention / instant-purging policies with 3PL partners.

Why keep shipping data for up to 90 days if the delivery is already confirmed? That’s a 90-day window for a honeypot.

reply

I’m glad I didn’t order one after the CC fiasco

reply
under our policy they must delete or anonymize it 90 days after delivery.

I'm curious how, if at all, this is verified, or even verifiable.

reply

i do not think it is possible to verify the deletion of data.

reply

Plus, kind of doesn't matter if it's leaked because the thief will definitely not delete it.

reply
companies don't just keep the logistics in house

One need to delegate if the aim is to scale

reply
3 sats \ 0 replies \ @fifoofa 14 Aug -30 sats

the part nobody can answer is how trezor verifies shipmonk actually deleted anything. you can't audit a third party's purge, so the only real fix is not handing over the full name, address and phone in the first place. hardware wallets make you self custody your keys and then ship your home address to a warehouse, that's the contradiction