Bitcoin hardware wallets Trezor and Ledger in hot water over data breaches
The wallets are supposed to be cold.

Image by stockphoto-graf | Shutterstock
- Trezor says a ShipMonk breach affected about 81,000 customers, far more than first reported.
- Exposed Trezor order data included names, shipping addresses, phone numbers, and email addresses.
- Trezor urged customers to watch for scam emails, calls, letters, and physical security risks.
- Ledger faces a class-action lawsuit over a 2023 data breach it allegedly downplayed.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Trezor says a wider ShipMonk breach affected about 81,000 customers as Ledger faces a lawsuit.
After the Coldcard crisis in the bitcoin (BTC) hardware wallet industry this past August, September has brought new data breach-related challenges for Trezor and Ledger, which are so-called cold wallet manufacturers.
In the first days of this month, Czech Republic-based Trezor disclosed that around 81,000 of its customers were affected by a personal data leak, or almost 6 times more than initially thought.
Meanwhile, Ledger was hit with a class-action lawsuit over a 2023 data breach.
The Trezor team said its shipping provider, ShipMonk, disclosed that another 67,000 US clients who bought these hardware wallets between November 2019 and August 2021 were affected by the breach, initially reported in August this year. Back then, Trezor said that ShipMonk had experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses.
According to the initial information, this breach affected almost 14,000 customers in the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal who received their orders between the 10th of May and the 8th of August 2026.
In an update on the situation, Trezor said that throughout its entire relationship with ShipMonk, it "repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications."
"We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems," Trezor said, urging its customers to be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Meanwhile, France-based Ledger, which has suffered 2 personal data leaks related to third-party incidents throughout its history, is now facing a lawsuit over one of them.
According to Ariel Givner, corporate and intellectual property counsel in fintech, the cryptoasset hardware wallet manufacturer was hit with a class action over a 2023 data breach that it allegedly downplayed and "failed to timely and fully disclose it."
"Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers' [personally identifiable information]," the complaint reads.
Back then, in 2023, the company also said that due to the exploit, "a low volume of users fell into the attack and signed transactions draining their signer."
Meanwhile, in 2020, 292,000 Ledger customers were impacted by a Shopify breach.