KEY TAKEAWAYS

  • The recent stories concern customer and order records held by external service providers. They are not evidence that private keys were extracted from Trezor or Ledger devices.
  • Trezor says a ShipMonk incident affected roughly 81,000 customers, with exposed fields potentially including names, email addresses, phone numbers, shipping addresses and order numbers.
  • Ledger is facing a proposed class action concerning past data incidents and disclosure practices. The allegations remain subject to litigation and should not be treated as final findings.
  • The immediate danger is highly targeted phishing: convincing calls, emails, letters and fake recovery instructions built around genuine customer details.
  • If your recovery phrase remains private and you have not approved a suspicious transaction, a customer-data incident alone usually does not require moving your assets.

When a hardware wallet company appears in a breach headline, it is natural to wonder whether the crypto secured by its devices is at risk. The answer depends on which layer was compromised. A stolen customer database and an extracted private key are both serious events, but they create very different problems.

Names, addresses, phone numbers and order details cannot sign a blockchain transaction. They can, however, tell a criminal who may own crypto, which device that person uses and what kind of support story is likely to sound convincing. That makes the next phishing attempt far more dangerous.

What happened at Trezor and Ledger

Trezor: retained shipping records exposed at ShipMonk

Trezor disclosed in August 2026 that ShipMonk, one of its shipping providers, had suffered a data breach. The first notice covered nearly 14,000 customers. In early September, Trezor said the scope was larger: records from its earlier relationship with the provider, spanning November 2019 through August 2021, had apparently remained in ShipMonk's systems and exposed data relating to approximately 67,000 additional U.S. customers.

The total impact was therefore about 81,000 customers. Depending on the record, the exposed fields could include a customer's name, email address, phone number, delivery address and order number. Trezor said it had repeatedly received written assurances that older records had been deleted.

This incident took place in the commerce and delivery layer. It did not disclose recovery phrases from Trezor devices, and it was not presented as a compromise of the system that generates and protects private keys.

Ledger: litigation over earlier incidents

Ledger is separately facing a proposed class action in the United States. The plaintiff alleges that the company mishandled or inadequately disclosed a 2023 incident and argues that exposed personal information later enabled convincing social-engineering attacks and financial loss.

Those are allegations in an active legal dispute, not final findings by a court. The case has nevertheless renewed scrutiny of Ledger's history of customer-data exposure, including the widely reported 2020 incident in which contact information associated with hundreds of thousands of customers became public.

The distinction matters: neither story means that every Trezor or Ledger device can be remotely opened or that an attacker automatically gained the keys required to move customers' assets.

A customer-data breach is not a wallet breach

Question Customer or order data exposed Recovery phrase or private key exposed
What is affected? Contact, delivery and purchase records The secret material that controls the wallet
Can it move funds by itself? No. The attacker still needs to deceive the owner or find another route Yes. Someone holding the secret can recreate the wallet and sign transfers
Main risk Targeted phishing, impersonation, account takeover and physical targeting Direct loss of crypto assets
Appropriate response Harden communications and verify every request independently Create a new wallet and move assets promptly

A hardware wallet is designed to keep signing keys isolated from an internet-connected phone or computer. A failure in an online store, support system or delivery provider does not automatically break that isolation.

Yet the device being intact does not make the incident harmless. A caller who already knows your full name, delivery address, approximate purchase date and device model can sound remarkably credible. Personal details should never be accepted as proof that someone genuinely represents a wallet company.

Why order records create real risk

A hardware wallet purchase can identify someone as a likely self-custody user. Criminals can use that signal to prioritize targets and tailor a script around a specific brand or product.

  • Fake security notices may direct the customer to a cloned website that requests a recovery phrase.
  • Impersonation calls can cite accurate order information before asking the user to install software or perform a “verification” transfer.
  • Letters and parcels can be sent to a real address with a QR code for a fabricated replacement or refund process.
  • Account attacks may target the exposed email address or phone number, including attempts to take over the mobile number.
  • Physical-security concerns become more serious when a home or office address is tied to a crypto-related purchase.

Non-negotiable rule: Trezor, Ledger, a retailer or legitimate support agent will not need your recovery phrase or private key to verify your identity, update firmware, replace a device or investigate a data incident.

What hardware wallet owners should do

Open official channels yourself

Do not follow links in an unexpected email, text message or direct message. Type the official web address yourself, open the app you already installed, or contact SIAMBC using the details shown on our website.

Do not trust a caller because the details are accurate

Correct names, addresses and order numbers may have come from the compromised dataset. They do not authenticate the person contacting you.

Secure the accounts around the wallet

Use a unique password for email, enable multi-factor authentication with an authenticator app or security key, and ask your mobile provider about a port-out or SIM-transfer PIN.

Verify every transaction on the hardware wallet

Read the destination address, network and amount on the device itself. Never approve a transaction because a supposed support agent says it is needed to “protect,” “validate” or “synchronize” the wallet.

Expect delayed attacks

Leaked data can be reused for years. A long gap between the breach and a phishing message does not make the message more legitimate.

What to do if you disclosed your recovery phrase

If you entered the phrase on a website, shared it in a chat, read it over the phone or typed it into untrusted software, treat the original wallet as compromised even if no funds have moved yet.

  1. Stop communicating with the person requesting the secret.
  2. Create an entirely new wallet on a trusted device and record a new recovery phrase.
  3. Transfer remaining assets to addresses generated by the new wallet, carefully checking the network and address on the device screen.
  4. Preserve suspicious messages, URLs, phone numbers and transaction records in case you need to report a loss.

Resetting a device and restoring the old phrase does not solve the problem. The attacker still knows the same secret and can recreate the wallet elsewhere.

Reducing risk when buying a hardware wallet

  • Buy from a verifiable authorized reseller with clear after-sales support.
  • Initialize the device yourself and never use a recovery phrase supplied in the box.
  • Install companion software only from the official website or app store listing.
  • Do not publish photos of shipping labels, serial numbers or order confirmations.
  • Consider a dedicated email address for financial and security services.
  • Keep the recovery phrase offline. Do not photograph it or store it in cloud notes.

SIAMBC customers who receive suspicious communications mentioning an order can end the conversation and contact us again through the details published on the SIAMBC website. Never send us a recovery phrase, private key, PIN or wallet password.

Frequently asked questions

Should I replace my hardware wallet?

Not merely because customer records were exposed. Replacing the device does not erase leaked contact information. If the wallet functions normally, its recovery phrase remains private and there are no unauthorized transactions, the more relevant response is stronger phishing awareness.

Should I move all crypto away from Trezor or Ledger?

A customer-data incident alone generally does not require an emergency transfer. First confirm that the recovery phrase has never been shared, inspect account activity and avoid acting on unsolicited instructions.

What if a letter arrives at my home?

Do not trust it simply because your address is correct. Avoid its QR codes and phone numbers. Verify the message through contact details you locate independently.

Can support recover or verify my recovery phrase?

No. A legitimate support team cannot view, retrieve or replace it for you and should never ask you to disclose it.

Does the Ledger lawsuit mean the company has already been found liable?

No. A complaint states the plaintiff's allegations. Liability and damages remain questions for the legal process unless the parties reach a settlement or a court issues a final decision.

Conclusion

The Trezor disclosure and litigation involving Ledger demonstrate that hardware wallet security extends beyond chips and firmware. Order databases, shipping partners, support systems and retention policies all shape the user's real-world exposure.

The practical lesson is not that hardware wallets have stopped working. It is that leaked customer data can make the next scam unusually persuasive. Keep the recovery phrase offline, verify every transaction on the trusted display and initiate contact through official channels rather than responding to an urgent message.

As long as the recovery phrase and private key remain secret, and the owner refuses suspicious approvals, a hardware wallet continues to provide the isolation it was designed to deliver.

Information reviewed on September 21, 2026. Written by Bank for general education only; this is not legal or investment advice.

Latest Stories

View all

Trezor Safe 5 และ Ledger Flex ของจริงอยู่หน้าฉากเตือนภัยข้อมูลลูกค้าและการโจมตีแบบฟิชชิง

Trezor and Ledger Customer Data Breaches: Are Your Hardware Wallets Still Safe?

Customer and order records linked to Trezor and Ledger have raised new security concerns. Here is what happened, what remains safe, and how hardware wallet owners can avoid targeted phishing.

Read moreabout Trezor and Ledger Customer Data Breaches: Are Your Hardware Wallets Still Safe?

Equity ownership documents transitioning into digital ledger blocks inside a modern capital market

Real Stocks Are Moving Onchain: How the SEC's New Framework Works

The SEC has opened a controlled five-year pathway for real tokenized U.S. stocks. Here is how trading venues, shareholder rights, AMMs, issuer safeguards and investor risks fit together.

Read moreabout Real Stocks Are Moving Onchain: How the SEC's New Framework Works

A real Ledger Flex beside an empty tray, illustrating wallet recovery after a device is lost

Lost Your Ledger? What Happens to Your Crypto and What to Do Next

A lost Ledger does not mean lost crypto. Learn how to assess exposure, restore safely on a replacement device, and move funds when your recovery details may be compromised.

Read moreabout Lost Your Ledger? What Happens to Your Crypto and What to Do Next