Full-Time
Posted on 9/8/2026
Global e-commerce order fulfillment and warehousing
No salary listed
Fort Worth, TX, USA
In Person
Bachelor's
See people who can refer or advise you
ShipMonk provides e-commerce order fulfillment as a 3PL, using a global warehouse network (US, Canada, Mexico, UK, and Europe) to store inventory closer to customers for faster shipping. It automates order processing through a platform that integrates with over 100 marketplaces and offers real-time tracking, plus inventory management tools to edit orders before shipment and view detailed logs. It differentiates itself with an agile, personalized fulfillment approach and broad platform integrations rather than traditional 3PL/4PL models, supported by its warehouse network and fast shipping options. The goal is to help e-commerce brands scale by delivering fast, reliable fulfillment and near-market inventory.
Company Size
1,001-5,000
Company Stage
Growth Equity (Venture Capital)
Total Funding
$365.1M
Headquarters
Fort Lauderdale, Florida
Founded
2014
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Professional Development Budget
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted TheHackerNews 05 Sep 2026
Trezor says ShipMonk breach exposed 67,000 U.S. Customers' data it said was deleted. by admin | Sep 5, 2026 Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
Trezor breach worse than reported: another 67,000 US customers exposed. September 4, 2026 Bitcoin Magazine general Negative Hardware wallet manufacturer Trezor has confirmed that a data breach affecting its customers is significantly worse than initially disclosed, with an additional 67,000 US customers now identified as exposed after third-party logistics partner ShipMonk failed to delete customer data as required. The revelation expands the scope of one of the most serious crypto hardware wallet security incidents in recent memory, raising urgent concerns about supply chain data security for Bitcoin (BTC) and cryptocurrency hardware storage users. ShipMonk's failure to purge sensitive customer records means tens of thousands of Trezor users - individuals who specifically chose hardware wallets for enhanced crypto security - now face elevated risks including phishing attacks, SIM-swapping attempts, and physical theft targeting, as bad actors may access names, addresses, and order details. This incident highlights a critical and often overlooked vulnerability: even the most secure cold storage devices depend on third-party fulfillment and logistics partners whose data practices may not meet the security standards crypto users expect. The Trezor breach arrives as hardware wallet adoption is growing alongside rising Bitcoin prices and increased mainstream crypto ownership, making vendor due diligence and data minimization practices more urgent than ever. Affected Trezor customers should immediately review account security and enable all available two-factor authentication options, while the industry watches to see whether regulators will use this breach to push for mandatory data retention standards across crypto hardware supply chains. Trezor said that its third party shipping partner, ShipMonk, had not erased customer data.
Wave of crypto hardware wallet data breaches hits SafePal, Trezor, and Bits of Gold - Nearly 250,000 users exposed in weeks. A cluster of data breaches has swept across the cryptocurrency hardware wallet industry over the past several days, exposing personal information belonging to tens of thousands of customers at SafePal and Trezor - two of the most widely used hardware wallet manufacturers - while a separate incident at Israeli crypto broker Bits of Gold has potentially compromised data for another 200,000 users. None of the breaches exposed seed phrases, private keys, or funds directly, but security researchers warn the leaked personal information creates serious downstream risks for crypto holders, from targeted phishing to physical "wrench attacks." SafePal: Nearly 40,000 Customers Affected SafePal disclosed on August 16 that it had identified an authorization flaw in the order-tracking function of a plug-in connected to its customer order system. Under specific conditions, the flaw allowed unauthorized third parties to access order information belonging to other customers. The company said it remediated the vulnerability upon discovery and implemented additional security measures. According to SafePal's, the exposed data affects customers who placed orders between March 2, 2025, and April 11, 2026, and includes names, email addresses, shipping addresses, phone numbers, and purchase details. In total, SafePal confirmed the incident affects approximately 39,798 customers. All affected users were individually notified by email from [email protected] on August 16, with the subject line "[Important] Your SafePal Order Information Has Been Affected." SafePal was explicit that seed phrases, private keys, and wallet passwords were not exposed in the breach, meaning affected users do not need to move their assets solely because of this incident. However, the company warned that anyone who separately entered or shared their seed phrase or private key in response to a suspicious message should treat that wallet as compromised, create a new wallet using a trusted SafePal device or official app, and transfer remaining assets immediately. SafePal's core security guidance for affected users is straightforward: never share a seed phrase, private key, or password with anyone - including someone claiming to represent SafePal support, since the company says it will never request this information by phone, email, or any other channel. Users should avoid clicking links or scanning QR codes in unsolicited messages, manually type SafePal's web address rather than following links (the company noted it has previously taken down phishing sites that replaced the letter "l" in its domain with a capital "I"), and report any suspicious contact through SafePal's official channels rather than social media. Trezor: Breach Traced to Shipping Partner ShipMonk Just three days before SafePal's disclosure, Trezor its own data exposure incident on August 13, though the root cause differed meaningfully. According to Trezor's official blog post, the breach originated not from Trezor's own systems but from ShipMonk, one of the company's third-party shipping and fulfillment providers, which experienced a data breach exposing customer order information. Trezor stated plainly that its hardware devices remain secure and were not compromised in any way. The exposed data includes full names, shipping addresses, phone numbers, and email addresses tied to orders shipped between May 10 and August 8, 2026, specifically affecting customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor provided a precise breakdown of the incident's scope:" The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)." The company attributed the relatively contained scale of the breach to its strict 90-day data storage policy - a retention limit it says it successfully negotiated with fulfillment partners as well, meaning older order data had already been deleted before the breach occurred. Customers uncertain whether they were affected were advised to check their inboxes for a notification from [email protected]. Trezor's Privacy Recommendations Going Forward In response to the incident, Trezor outlined several steps customers can take to reduce data exposure on future orders. The company recommended using an anonymous email address not linked to one's real identity when placing orders, and suggested paying with cryptocurrency rather than a credit card where possible - or using disposable digital cards for online purchases if crypto payment isn't an option. Trezor also suggested using a P.O. Box to limit address exposure, while noting that identification is typically still required for package collection and that postal services retain their own data records regardless. Trezor additionally teased an upcoming "Anonymous Delivery" feature, designed to let customers receive hardware wallets more privately through a dedicated checkout process, locker pickup options, neutral packaging, generic sender details, and automatic deletion of shipping identifiers following delivery. Bits of Gold: A Third Breach in Israel Adding to the pattern, Bits of Gold - Israel's largest regulated cryptocurrency broker - separately reported a potential data breach affecting up to 200,000 clients, though fewer technical details have been made public compared to the SafePal and Trezor incidents. The near-simultaneous timing of three separate crypto-industry data exposures within roughly the same week has amplified concern across the sector about the security practices of vendors and partners handling crypto customer data. Why These Breaches Matter Even Without Stolen Funds Security researchers have repeatedly emphasized that even when seed phrases and private keys remain untouched, breaches exposing names, addresses, and purchase details tied specifically to cryptocurrency hardware purchases carry outsized risk compared to typical e-commerce data leaks. A leaked customer list confirming that a specific person owns a hardware crypto wallet - and knows their home address - provides exactly the targeting information needed for sophisticated phishing campaigns, fraudulent "customer support" outreach, and, in more extreme cases, physical confrontation or coercion, sometimes referred to in the industry as "wrench attacks." Part of a Broader Pattern of Sensitive Data Exposure These crypto-specific incidents are unfolding against a backdrop of other major data breaches with similar targeting implications. In France, a leak reportedly exposed data belonging to 678,000 taxpayers, including income figures, addresses, and property details - information that, while not crypto-related, provides exactly the kind of financial profiling criminals use to identify and select wealthy targets for extortion or robbery, independent of whether victims hold cryptocurrency at all. What Affected Users Should Do Now For anyone who has purchased a hardware wallet from SafePal or Trezor, or who holds an account with Bits of Gold, security experts recommend treating any unexpected communication referencing a past purchase - by phone, email, text, or physical mail - with heightened suspicion. This includes unsolicited firmware update requests, refund offers, or "support" calls asking for seed phrases or private keys under any circumstance. Genuine hardware wallet companies do not request this information through outbound contact. Users should verify any communication through official company channels by manually navigating to the company's known website rather than clicking links, and report suspicious contact through the companies' dedicated reporting channels rather than social media, where scammers can more easily impersonate support staff.
Israeli crypto broker Bits of Gold discloses breach tied to third-party software attack. Bits of Gold, Israel's largest regulated cryptocurrency broker, has told customers that a breach of a vendor system may have exposed personal and financial data, part of a wider software-supply-chain attack hitting hundreds of companies worldwide. Bits of Gold, a Tel Aviv-based cryptocurrency broker holding financial services license 56716 from Israel's Capital Market, Insurance and Savings Authority, notified customers on Aug. 16 that unauthorized access had been found in a third-party system the company uses for customer support and data analysis. The company said it detected the intrusion several days before the notice, cut off the compromised system from its data sources, and alerted regulators. The breach traces back to a software vendor used by Bits of Gold, not a direct strike on the broker's own network. Bits of Gold said it was one of potentially hundreds of businesses worldwide caught up in the same attack on the software provider, and that available information does not indicate the company was deliberately singled out. The identity of the software vendor has not been made public. An initial internal review found that intruders may have reached names, national identification numbers, email addresses, phone numbers, IP addresses, bank account numbers and public cryptocurrency wallet addresses tied to customer accounts. Bits of Gold said digital holdings, account passwords, scanned identification documents, full card numbers and card security codes were not affected, noting that it does not store customers' private keys or complete card data. The company said it has so far found no sign that any of the exposed data has been used maliciously. How many customers were affected has not been established. Figures placing the number near 200,000 have spread through social media and crypto news outlets, but Bits of Gold has not confirmed that count. The notice sent to customers did not specify a number of affected records, and the company's website lists more than 300,000 total customers. No other Israeli firm had been identified as caught up in the same attack at the time of the disclosure. "Similar to other financial entities, the company will never ask you to provide a password, verification code, or private key, and will not ask you to transfer money or digital assets to another wallet," Bits of Gold said in its customer notice. The company urged customers not to hand over passwords, verification codes or private keys, and not to send money or crypto assets in response to unexpected contact. Bits of Gold said it has engaged a specialized cyber incident response firm to conduct a full review and that it continues to monitor its systems. It said its platform remains fully operational and that customers do not need to take any account action at this time. The disclosure follows a separate third-party breach in the crypto industry in which an incident at fulfillment company ShipMonk exposed personal data belonging to 13,689 customers of hardware wallet maker Trezor, raising similar phishing concerns across the sector. Bits of Gold has not disclosed the confirmed number of affected customers, the identity of the compromised software vendor, or whether the exposed data has been used for fraud. Those details remain outstanding as the investigation continues.