
Trezor says a recent breach at logistics provider ShipMonk exposed the personal and shipping information of another approximately 67,000 customers, dramatically expanding the scope of an incident first disclosed in August.
The newly identified records belong to US customers who ordered Trezor products between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor said ShipMonk informed it on September 2 that the breach was larger than previously reported. The hardware wallet maker added that it had repeatedly received written assurances during its relationship with ShipMonk that older customer data had been deleted in accordance with contractual requirements and its data-retention policy.
Despite those assurances, the historical order records remained in ShipMonk's systems and were exposed in the breach.
Trezor develops cryptocurrency hardware wallets that store private keys separately from internet-connected devices. ShipMonk served as one of its fulfillment partners, holding inventory and processing customer shipments, which required access to names, addresses, phone numbers, and email addresses.
The company initially disclosed the incident on August 13 after ShipMonk reported unauthorized access to systems containing Trezor order information.
At the time, Trezor said 13,689 customers were affected, including 11,742 whose names, emails, phone numbers, and shipping addresses were exposed, and another 1,947 whose exposure was initially described as limited to names, cities, and email addresses.
That disclosure primarily covered customers receiving orders between May 10 and August 8, 2026, across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor had said the impact was limited by a requirement that fulfillment partners delete or anonymize customer information after 90 days.
The discovery of the older US records shows that ShipMonk had retained data well beyond that period.
Trezor says its own infrastructure and hardware wallets were not compromised, and there is no indication that wallet backups, private keys, or device data were exposed.
However, the leaked information creates a significant phishing and physical-security risk because attackers can identify individuals associated with cryptocurrency hardware wallets and target them with convincing emails, phone calls, fraudulent letters, or impersonation attempts.
Trezor says it has notified all newly affected customers directly from help@trezor.io. Customers who did not receive a notification are not considered affected.
Users whose information was exposed should be particularly suspicious of messages requesting urgent action and should never share a wallet backup or recovery seed, or enter it into a website, regardless of who appears to be requesting it.







Leave a Reply