Trezor Data Breach Expands to 80,700 US Users as Firm Blames Shipping Partner ShipMonk
Key Takeaways
- •Trezor disclosed that 67,000 additional U.S. customers were affected by the ShipMonk data leak, raising the total from roughly 14,000 to about 80,700 users.
- •The newly exposed records cover U.S. orders placed between November 2019 and August 2021, despite ShipMonk having repeatedly provided documentation affirming that data older than 90 days had been deleted.
- •Trezor stated its own systems were not breached, with no devices, private keys, or wallet backups exposed, and placed responsibility on the shipping provider.
- •The leaked customer list elevates targeting risk because hardware wallet buyers are likely cryptocurrency holders, and some Trezor and Ledger owners already received forged scam letters in February.
- •Phishing and social engineering scams accounted for $306 million of the $482 million in cryptocurrency stolen in the first quarter, according to blockchain security firm Hacken.

In an update issued on Friday, Trezor disclosed that the data leak stemming from its shipping partner, ShipMonk, was significantly worse than initially believed. The personal information of an additional 67,000 U.S. users — including names, addresses, phone numbers, email addresses, and order data — was exposed, bringing the total number of affected users to 80,700 and putting holders of Trezor wallets at risk.
The newly identified batch of data covers orders placed by U.S. customers between November 2019 and August 2021, as Trezor announced in a post on X on Friday. Some of that information is nearly seven years old. That detail matters: when Trezor first announced the breach in August, the 90-day data deletion policy implemented by its fulfillment partner had been credited with limiting the number of impacted users.
The case underscores a broader risk in the hardware wallet industry: even when a vendor's own security is intact, outsourcing fulfillment and customer service introduces third parties that hold sensitive customer records. Trezor, like rival Ledger, relies on external logistics providers to ship devices worldwide, meaning the privacy of customers depends partly on partners whose data-retention practices they do not directly control.
Trezor data exposure surges to 80,700 users
Trezor explained that it had repeatedly asked ShipMonk for documentation confirming that order data older than 90 days had been deleted. Each time, the company received affirmative responses. Trezor now says those documents turned out to be incorrect, and according to reports, the firm has placed the blame squarely on the shipping provider for retaining data it had promised to delete.
The new figures far exceed earlier estimates. In August, Trezor had put the exposure at roughly 14,000 people. ShipMonk then reported its updated findings to Trezor two days before Friday's disclosure, raising the tally to approximately 80,700 users.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…
— Trezor (@Trezor) September 4, 2026
Trezor clarified that its own systems were not compromised. No devices, private keys, or wallet backups were exposed, as the breach occurred entirely on the logistics side. However, customer contact details and shipping information were compromised. The episode nonetheless illustrates the limits of vendor assurances: contractual deletion policies and confirmatory documentation proved insufficient on their own to guarantee that data was actually removed, a challenge that extends well beyond the crypto industry to any company that entrusts customer records to outside processors.
How a mailing list becomes a weapon
The principal danger lies in targeting. A leaked mailing list of verified hardware wallet owners — including their home addresses — allows attackers to pursue those specific individuals with phishing attempts by email, phone calls, and even physical mail. Trezor advised affected users to remain vigilant against such attempts and highlighted the threat to personal safety. Because hardware wallets are marketed as a way to self-custody significant crypto holdings, a list of their buyers is effectively a list of people likely to hold digital assets, which raises the stakes compared with a generic retail mailing list.
That threat is already tangible. In February, owners of Trezor and Ledger wallets received forged letters printed with holograms, QR codes, and even fake executive signatures, urging them to carry out a bogus security test or face account lockout. Cybersecurity expert David Sehyeon Baek noted that a forged letter delivered to a real name and address changes the psychology of the scam.
The magnitude of the phishing problem
An impersonation scam does not require a technical exploit to drain a user's wallet. Such schemes already dominate cryptocurrency loss figures: blockchain cybersecurity firm Hacken found that phishing and social engineering scams accounted for $306 million of the $482 million total stolen in the first quarter of the year. In July, one investor nearly lost $1 million after confirming a malicious token transaction on Ethereum.
This is also not the first time Trezor has dealt with a breach involving exposed user contact details. In January 2024, the company revealed that roughly 66,000 customers who had contacted its support team since December 2021 were exposed to phishing scams. With the affected population now several times larger, customers who ordered a Trezor device between late 2019 and mid-2021 may continue to see targeted scam attempts — by email, phone, or post — for some time, and further updates from Trezor or ShipMonk on the final scope of the retention failure remain possible given how the figures have already been revised upward once.