A Short History of Crypto Customer Data Leaks, and What They Teach
Image Source: depositphotos.com
In August 2026, Trezor told about 13,700 US customers that their names, email addresses, phone numbers and shipping addresses had been stolen in a breach at ShipMonk, a logistics company that had once handled its orders. Weeks later the number rose to roughly 80,700, after the company found the stolen records also covered orders placed between late 2019 and mid-2021. Customers who had bought a wallet five years earlier, and long since forgotten the delivery, were suddenly on a list in the hands of an extortion group.
The incident is the latest in a pattern that has repeated across the crypto industry since 2020. Looking at the major leaks in order shows how the risk has shifted, and why the most useful protection is often simply sharing less in the first place.
2020: Ledger and the address list
The modern story starts with Ledger. In June 2020 attackers accessed its e-commerce database, and in December a file appeared on a hacker forum with the names, postal addresses and phone numbers of 272,853 buyers, plus 1,075,382 newsletter email addresses. No device was compromised, but the data fueled years of phishing, including fake Ledger Live updates built to capture recovery phrases. It made the uncomfortable point that owning a hardware wallet was itself valuable information. Years later, LessKYC, an independent review directory that scores crypto and online services on how much personal data they collect, still notes the 2020 breach on Ledger's listing.
2022 to 2024: the vendor problem
The next wave rarely came through the crypto companies' own systems. It came through the suppliers around them.
-
Gemini, 2022: a third-party vendor exposed contact details for about 5.7 million users.
-
Kroll, August 2023: a mobile carrier employee moved a Kroll staff member's phone number to an attacker's device, giving access to files on claimants in the FTX, BlockFi and Genesis bankruptcies. Phishing emails posing as FTX followed almost immediately.
-
Trezor, January 2024: attackers reached a third-party support portal and obtained names and email addresses for nearly 66,000 users.
-
Gemini, June 2024: a payments provider breach exposed the names and bank account numbers of about 15,000 customers.
2025: when identity documents leaked
The most serious case so far came from Coinbase. In May 2025 it disclosed that criminals had bribed overseas support contractors to pull customer records, then demanded $20 million, which Coinbase refused to pay. The data for 69,461 people included names, addresses, partial Social Security numbers, masked bank details and images of government ID. Coinbase estimated the cost at between $180 million and $400 million. Regulated exchanges must collect identity documents by law, which means they hold exactly the records criminals value most, and the people with access to them become targets.
2026: the partners of partners
This year added two more. In January, Ledger warned customers that Global-e, an e-commerce partner, had leaked names and contact details. Then came the ShipMonk breach, carried out through a flaw in an analytics tool the logistics firm used. Each step removed from the brand you trusted is another company holding a copy of your data.
What the pattern teaches
-
Data you hand over is copied to payment processors, shippers and support desks.
-
Old records persist long after you stop thinking about them.
-
A name, email and confirmed purchase is enough for convincing phishing.
-
Where the law requires identity checks, the data will be held. Everywhere else, less collected means less to lose.
That last point is why it pays to compare services on their data practices before you sign up, using reviews such as LessKYC's alongside the company's own claims. Paying merchants directly in crypto also keeps your card details out of one more database, and XMRList lists more than 1,400 businesses and services that accept Monero.
Physical goods still need an address, but a parcel doesn't have to announce what is inside. BTC Mints, a precious metals dealer that accepts Bitcoin, Monero and other coins, ships insured, tracked parcels in plain packaging, the kind of habit that limits the damage if a courier's records ever leak.
If your data is already out there
-
Treat any message that references a real order or account as suspicious, however accurate it looks.
-
Never type a recovery phrase anywhere except the device it belongs to.
-
Ask your mobile carrier for a port-out PIN or SIM change lock.
-
Use a separate email address or alias for crypto accounts and purchases.
-
Consider a parcel locker or pickup point for future hardware orders.
The lesson most people missed
Six years of leaks all point one way: no company can lose data it never collected. You can't control a vendor's security, but you can control how many companies hold your details and how much each one gets.