Hardware wallets are designed to protect cryptocurrency keys, but a breach involving shipping records shows how the personal information used to deliver them can remain a security risk years after a purchase.
Trezor said in a 4 September update that about 67,000 additional customers in the United States had been affected by a breach at ShipMonk, the company responsible for delivering its devices. The records covered orders made between 2019 and 2021. Trezor said ShipMonk had previously provided written assurances that the information had been deleted.
The total number of affected customers is now 80,689.
Trezor said its own systems and devices were not compromised and that the contents of parcels were not exposed. The leaked information was limited to contact and delivery details, meaning no funds were stolen or misappropriated.
However, a name and address connected to a hardware-wallet purchase can give criminals a more credible way to target an owner. A message that refers to a genuine order, or a letter delivered to the correct home, may appear far more convincing than a generic phishing attempt.
Hardware wallets store private keys on a dedicated device. Those keys authorise transactions on the Bitcoin network, while the device can approve a payment without revealing the key to the computer running the wallet software. That separation means a compromised computer does not automatically result in lost funds.
Owners also need a method of recovering access if a device is lost or damaged. Wallet backups, commonly made up of a sequence of words, can restore a wallet on another device. But anyone who obtains that information may gain access to the funds. Trezor advises customers not to share backups or keep digital copies of them.
Ledger has recorded phishing campaigns in which victims received physical letters telling them to scan a code or visit a website and enter their recovery words. Such attacks demonstrate how stolen delivery data can be used to make a fraudulent request look official.
A shipping record does not prove that someone still owns a wallet, Bitcoin or any particular amount of cryptocurrency. The device may have been a gift, sold on, abandoned or used to hold coins that have since been sold. Even so, it can provide enough information for a criminal to choose a target.
The distinction between different types of data is important. A name and delivery address can identify where a device was sent and provide a method of contact, but cannot show whether the recipient currently owns Bitcoin. A public wallet address can reveal associated transactions and balances, but not necessarily the owner’s real-world identity. A private key authorises spending from the coins it controls, while a wallet backup can restore access. Additional passphrases or systems requiring several backup shares may also be needed.
Why old delivery records matter
Shipping information is needed to route parcels, resolve failed deliveries and process returns. Hardware-wallet companies operating internationally often rely on external fulfilment providers to perform those tasks.
The risk arises when temporary operational data becomes a long-term corporate record. Information can remain in database copies, customer-support exports and backups after it has been removed from the system employees use routinely. Deleting a record therefore requires more than removing it from one application.
The Federal Trade Commission advises businesses to collect and retain sensitive information only when there is a legitimate need, understand where it is stored and shared, and dispose of it securely. The guidance also applies to service providers: outsourcing a task does not remove a company’s responsibility for how customer data is handled.
Contracts commonly include deletion requirements, but a clause and a supplier’s assurance are not the same as evidence that every relevant system has removed the information. Companies need to set retention periods, demand proof and test whether contractors are following those terms.
Unlike a payment card or password, a home address cannot simply be replaced when compromised. Moving house may not remove the connection between an old address and other records, and copied data cannot be recovered from everyone who received it.
Customers can reduce some risks by using parcel lockers, neutral packaging or separate contact details for online purchases. Those measures have limits: locker operators may require identification, payment providers can retain billing information, and plain packaging does not erase retailer records. Unfamiliar or second-hand sellers may also make a device’s origins harder to verify.
For manufacturers, better protection must begin before a breach occurs. That means collecting less information where possible, separating data that does not need to travel together and obtaining evidence that contractors delete records when their work is complete.
A hardware wallet protects private keys from an ordinary computer. Protecting the person who buys it also depends on the manufacturer, warehouse and fulfilment partner ensuring that personal information does not outlive its legitimate purpose.
