Scott Melker discusses the recent security breach at Trezor’s shipping partner ShipMonk.
Make sure to also check out Yahoo Finance’s new crypto hub to find the latest crypto-related news.
Trezor warns 14,000 customers after fulfillment partner suffers data breach. The incident marks the first time Trezor customers’ shipping addresses were exposed. So first, I’ll dive into what happened. Then we’ll talk about what it means. So this is a breach at Trezor’s shipping partner, Shipmunk.
suit. It’s like chipmunk, but they get you killed.
Exposed information belonging to approximately 13,689 customers. For 11,742 of them, the compromised information included names, addresses, phone numbers, and emails. Another 1947 had just their names, cities, and emails exposed. So Treasure made it clear that there was no violation of private keys, the devices are safe, customer funds are SAAFU, not compromised.
That distinction matters technically, but criminals now potentially have a hit list of people who have bought hardware wallets and know where they live. So, let’s talk about this. The first risk, obviously, immediately is fishing. We saw this with the Ledger X uh uh the ledger data breach many, many years ago.
Uh I can’t remember the number, but tens of thousands of customers, their their data was given and every single one of them started getting emails and fishing attempts and attempts to steal all of their money. Okay, great.
The bigger problem right now is wrench attacks, which means physical attacks to try to steal people’s Bitcoin and crypto. And if you think I’m being hyperbolic, just take a look at what’s been happening in France over the past couple of years.
So in in case you missed the story, basically, wrench attacks started increasing in France from 2024 to 2025, 2026. There’s now been, I believe, over 70 attacks just this year, uh four or five X since 2024 when they started. It came out that uh basically because of reporting rules to the French equivalent of the IRS, everybody transparently gave the government all the information on the crypto that they held, and somebody at the government then sold that to criminals at €800 a pop.
And those people became targets. The founder of Ledger lost a finger. Literally, they cut his finger off in a 10 million euro ransom attempt. People’s wives and children have been kidnapped. And this is happening multiple times a month in France. Well, now Treasure has sent, you know, a letter to all these 14,000 people saying, you could be next. Right? Criminals now definitely will know exactly where you live and that you bought a hardware device. Now, some people have said to me, it’s no big deal. They don’t know how much you hold.
But they know that you hold enough that you care about buying a hardware device, you care enough about your self custody, and it’s probably a meaningful part of your wealth, and they know exactly where you live, what your email address is, what your phone number is, and how to find you. This is an absolute disaster.
I’m prone to hyperbole, but when you put this, you know, in conjunction with the Cold card hack that I told you about from just last week, that was an ongoing exploit, it really is damning for the self custody industry, right? We were told and telling people, not your keys, not your coins, be your own bank. But I didn’t know that being your own bank also meant in 2026 being your own bank security, which means having the uh weaponry and know-how to protect yourself physically from violence when somebody tries to rob your bank. We were also told, keep your keys yourself. Don’t trust exchanges. There’s too much counterparty risk.
But nobody talked about the counterparty risk of a data leak from the person you buy the hardware wallet from, or the counterparty risk of cold card having an exploit where you didn’t roll enough magic dungeons and dragons dice to generate a seed phrase.
We’re at the point where now the debate is if all these treasure people should have sent it to a P.O box to an anonymous address and not use their name and blah, blah, blah, blah, blah. Nobody wants to do that.
I do, in theory, believe in self-custody. Now you have to believe in multi-signature self-custody, which is something that I have done, and geographically setting yourself on a scavenger hunt for 100 days around the world just to be able to access $5 worth of your Bitcoin. But let’s be honest, for 95% of people at this point, nobody is going to go far enough down the rabbit hole to have the proper opsec to actually protect themselves. I don’t know what the answer is. I’m struggling with it. I’m not the guy who’s going to say just go buy an ETF because the issuers of the ETF are the very institutions that we got into Bitcoin to rage against in the first place.
But we have a very, very, very big problem right now. I mean, the hardware wallet works perfectly, the shipping spreadsheet is the attack surface. Like you really could not have uh predicted that.