Trezor, one of the best-known names in hardware cryptocurrency wallets, has confirmed that a data breach at its US fulfillment partner ShipMonk is significantly larger than the company first disclosed. The revised scope adds roughly 67,000 additional American customers to the incident, bringing the overall number of people affected to more than 80,000, and it raises uncomfortable questions about how long third-party vendors were holding onto data they were supposed to have deleted years earlier.
How the Breach Unfolded
The chain of events began when Metabase, an analytics platform used by ShipMonk, notified the fulfillment company on August 6 that its software had suffered unauthorized access. Investigators later tied the intrusion to a critical SQL injection zero-day in Metabase that gave attackers administrator-level access on compromised instances. ShipMonk reported the incident to Trezor on August 10, and Trezor issued its first public disclosure three days later.
What initially looked like a contained incident kept expanding. Trezor’s first update acknowledged that some of the exposed records involved older orders, but the full extent only became clear on September 2, when the company learned of a further batch of exposed data tied to a US partnership dating back to November 2019 through August 2021.
What Data Was Exposed
The breach touches two distinct sets of records. The originally disclosed batch covered orders placed between May and August 2026 from customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, and included names, email addresses, phone numbers, and shipping addresses for roughly 13,700 people. The newly confirmed batch, drawn from years-old US order records, exposed the same categories of personal information along with order numbers.
Trezor has been clear about what was not touched: its own internal systems were not breached, hardware wallet devices themselves remain secure, wallet backup seeds were never exposed, and physical parcel contents were not compromised. The risk here is squarely about the personal information tied to past purchases, not the cryptographic security of the wallets themselves.
A Data Retention Failure
The most striking detail in Trezor’s disclosure is not the breach itself but why years-old data still existed at all. Trezor’s policy requires fulfillment partners to delete or anonymize order data 90 days after delivery. According to the company, it had “repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk’s systems” when the breach occurred. In other words, a vendor’s failure to honor a straightforward data-deletion agreement is what allowed years-old customer records to become part of a 2026 breach.
Why This Incident Is Different for Trezor
Since its founding in 2013, Trezor has built its reputation on securing cryptocurrency rather than handling customer data incidents, and this marks the first time in the company’s history that a breach has exposed customer phone numbers and shipping addresses. That combination is particularly sensitive for a hardware wallet vendor, because it links real-world addresses to a strong signal that the resident owns cryptocurrency, a pairing that has previously been linked to targeted burglaries and extortion attempts against known crypto holders.
Risks Facing Affected Customers
Security researchers and Trezor itself have flagged two main categories of follow-on risk:
- Phishing and impersonation: Scammers can use the leaked names, emails, and phone numbers to impersonate Trezor, a bank, or an exchange, contacting victims by email, phone call, or physical letter in an attempt to trick them into entering a wallet recovery seed.
- Physical targeting: Because shipping addresses are now tied to confirmed hardware wallet purchases, affected individuals may face an elevated risk of being physically targeted by criminals seeking to coerce access to cryptocurrency holdings.
Trezor is directly notifying affected customers via email from help@trezor.io, and the company has stated that anyone who does not receive such a notification was not part of the leaked dataset.
What Trezor Recommends
The company is urging affected customers to treat any urgent request for personal information as hostile by default, and to verify any communication claiming to be from Trezor only through its official channels. Above all, Trezor reiterates its standing guidance: never type a wallet backup or recovery seed into a website, and never share it with anyone under any circumstance, regardless of how urgent or official the request appears.
Looking ahead, Trezor says it is preparing an “Anonymous Delivery” shipping option that would route packages through locker pickup points and automatically delete shipping identifiers after fulfillment, a change clearly designed to prevent a repeat of the exact failure mode that led to this breach.
Leave a Reply
You must be logged in to post a comment.