NewsCryptoTrezor Expands Data Breach Disclosure to 81,000 Customers, Raising Physical Security Concerns for Hardware Wallet Owners

Trezor Expands Data Breach Disclosure to 81,000 Customers, Raising Physical Security Concerns for Hardware Wallet Owners

Author: Metaverse Post·

Key Takeaways

  • Trezor expanded its breach disclosure to include an additional 67,000 U.S. customers, bringing the total affected to approximately 81,000.
  • The compromised records stem from former fulfillment partner ShipMonk and include names, email addresses, phone numbers, shipping addresses, and order numbers for orders placed between November 2019 and August 2021.
  • Trezor stated its own infrastructure and hardware wallets were not breached and that stored funds remain secure.
  • ShipMonk retained customer data for years despite contractual requirements and written assurances that it had been deleted, contrary to Trezor's 90-day deletion policy.
  • Trezor is developing anonymous delivery options and warned affected customers to be vigilant against scams and physical security threats, echoing the aftermath of the 2020 Ledger breach.
Trezor Expands Data Breach Disclosure to 81,000 Customers, Raising Physical Security Concerns for Hardware Wallet Owners

Trezor, a leading manufacturer of cryptocurrency hardware wallets, has substantially revised the scope of a data breach involving its former shipping partner, ShipMonk.

The company disclosed that an additional 67,000 U.S. customers who placed orders between November 2019 and August 2021 had their personal information compromised, dramatically expanding upon the approximately 14,000 individuals initially reported as affected on August 13.

The updated disclosure raises the total number of impacted customers to roughly 81,000. The initial breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers, along with partial data for another 1,947. The newly identified records contain comprehensive personal details, including names, email addresses, phone numbers, shipping addresses, and order numbers.

Trezor emphasized that its own infrastructure was not breached and that its hardware wallets remain fully secure. Hardware wallets such as Trezor's store users' private keys offline on the device itself rather than on internet-connected servers, which is why the compromise of shipping records rather than wallet systems does not affect the security of funds. All affected individuals have been contacted directly via email, and the company noted that customers who did not receive a notification are not impacted by this latest disclosure.

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…

— Trezor (@Trezor) September 4, 2026

Contractual Breaches and Physical Security Implications

The incident exposes critical failures in third-party data management and contractual compliance. Throughout its engagement with ShipMonk, Trezor repeatedly requested the deletion of customer information and obtained written assurances that the data had been removed in accordance with their contractual obligations and data protection policies.

Trezor maintained a strict policy requiring fulfillment partners to delete or anonymize order data within 90 days of delivery. The company expressed profound disappointment that these commitments were not honored, leaving sensitive information retained in ShipMonk's systems for years despite explicit written confirmation of its destruction. The widening scope of the disclosure, from roughly 14,000 to approximately 81,000 individuals, also illustrates how breaches involving third-party vendors are frequently revised upward as investigations progress, a pattern seen across many industries dependent on external logistics and fulfillment providers.

Beyond conventional concerns of identity theft and digital fraud, the breach underscores the distinctive physical security risks faced by cryptocurrency hardware wallet owners. The exposure of residential addresses linked to known purchases of devices designed to secure high-value digital assets creates vulnerabilities that extend well beyond typical phishing campaigns.

Trezor warned affected customers to exercise heightened vigilance regarding scam emails, fraudulent telephone calls, and deceptive correspondence, while explicitly acknowledging potential physical security implications for individuals whose home addresses are now publicly associated with cryptocurrency ownership.

The situation closely parallels the 2020 Ledger data breach, which exposed information belonging to over 270,000 customers and resulted in persistent social engineering attacks, scam phone calls, and physical threats that continued for years after the initial disclosure. The recurrence of such incidents highlights the urgent need for stronger oversight of fulfillment partners in the cryptocurrency hardware sector, and Trezor's development of anonymous delivery options may signal a broader industry shift toward minimizing the customer data that hardware wallet vendors and their vendors collect and retain in the first place.

In response, Trezor announced it is actively developing anonymous delivery options to protect customer information in future transactions. The company also reinforced its fundamental security guidance, advising users never to share wallet recovery phrases or enter them into any website under any circumstances.

Source: Metaverse Post