NewsCryptoTrezor Expands ShipMonk Breach Notification to 67,000 Additional U.S. Customers

Trezor Expands ShipMonk Breach Notification to 67,000 Additional U.S. Customers

Author: Crypto Adventure·

Key Takeaways

  • Approximately 67,000 additional U.S. customers who purchased Trezor devices between November 2019 and August 2021 had personal information exposed in the ShipMonk breach.
  • The initial disclosure on August 13 identified 13,689 affected customers, but newly discovered records show much older data persisted despite a 90-day deletion requirement.
  • ShipMonk had repeatedly provided written assurances that older shipping data had been deleted, conflicting with the retained 2019–2021 records.
  • Trezor confirmed that its systems, firmware, private keys and wallet backups were not compromised, as the exposure occurred within ShipMonk's fulfillment infrastructure.
  • Trezor is developing an Anonymous Delivery service featuring locker collection, neutral packaging and automatic deletion of shipping identifiers, targeted for Europe around September 2026 and the U.S. later that year.
Trezor Expands ShipMonk Breach Notification to 67,000 Additional U.S. Customers

Trezor has widened the scope of its ShipMonk data breach after discovering that personal information belonging to approximately 67,000 additional U.S. customers was exposed, with affected orders dating back as far as 2019.

The newly identified customers purchased Trezor devices between November 2019 and August 2021. The exposed records include names, email addresses, phone numbers, shipping addresses and order numbers, substantially broadening an incident that was initially believed to be limited largely to recent purchases.

The expansion illustrates a broader pattern in crypto-related security incidents: hardware wallets themselves are rarely broken into, but the surrounding ecosystem of shipping, marketing and third-party vendors has repeatedly become the weak point where customer data leaks. Because hardware-wallet security depends on private keys and recovery phrases remaining offline, attackers often target the human layer instead, using leaked personal data to reach device owners directly.

ShipMonk Retained Data Trezor Expected Deleted

The discovery directly conflicts with Trezor's customer-data retention policy. According to the company, ShipMonk had repeatedly provided written written assurances that older shipping information had been deleted in line with contractual requirements, Trezor's data policy and previous communications between the two companies.

The hardware-wallet maker first disclosed the ShipMonk breach on August 13 after learning that unauthorized actors had accessed customer information held by the logistics provider. That initial investigation identified 11,742 customers whose names, emails, phone numbers and shipping addresses were exposed, along with another 1,947 customers with partial exposure.

At the time of the first disclosure, a 90-day deletion requirement was expected to limit the breach to recent orders. The newly discovered 2019–2021 records demonstrate that substantially older customer information remained inside ShipMonk's systems despite those requirements.

The gap between contractual deletion commitments and actual data retention is a recurring problem in vendor-risk management: companies that outsource fulfillment typically rely on supplier attestations, and those assurances are only tested when an incident exposes what data actually persists inside the vendor's infrastructure.

Trezor emphasized that its systems, firmware, private keys and wallet backups were not compromised. The exposure occurred within ShipMonk's fulfillment infrastructure rather than in the hardware wallets themselves.

Shipping Data Creates Targeted Phishing Risk

Names, phone numbers and physical delivery addresses can provide attackers with enough information to construct highly personalized phishing attempts aimed specifically at known hardware-wallet owners. Knowing that a household received a hardware wallet years ago is valuable targeting information, since a credible-seeming message about a "device recall" or "backup verification" can reference a real order history.

Victims may receive fraudulent emails, phone calls or physical letters impersonating Trezor, cryptocurrency exchanges, banks or delivery companies. Trezor is instructing customers never to disclose or enter a wallet backup in response to any communication claiming that a device, account or recovery phrase requires urgent verification. Trezor has long stated that it will never ask customers for their recovery seed, a rule that applies to any unsolicited contact.

The company has previously dealt with third-party exposure risks. A separate Trezor.io incident in December 2025 involved suspicious activity linked to an external service, although no databases, devices or wallet software were compromised in that case.

Anonymous Delivery Plans Gain Urgency

Trezor is developing an Anonymous Delivery option designed to reduce the amount of personally identifiable information attached to hardware-wallet purchases. Planned features include locker collection, neutral packaging, generic sender information and the automatic deletion of shipping identifiers after delivery.

The service was targeted for availability in Europe around September 2026, with a U.S. rollout planned before the end of the year. The newly disclosed retention failure adds pressure to that timeline, since the incident demonstrates concretely how long customer shipping data can persist beyond a vendor's stated deletion window.

The newly discovered historical records increase the known exposure from the ShipMonk breach well beyond the original 13,689 customers, with approximately 67,000 additional U.S. buyers from November 2019 through August 2021 now being notified.

Source: Crypto Adventure