Trezor Data Breach Widens, Exposing 67,000 More U.S. Customers
Key Takeaways
- •Trezor announced that an additional 67,000 U.S. customers were affected by the ShipMonk data breach, bringing the total to 80,689 affected customers.
- •The newly exposed records involve U.S. orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses, and order numbers.
- •Trezor stated that its hardware wallets and internal systems were not compromised by the breach, which affected only data held by its shipping provider.
- •Trezor warned affected customers to be alert for phishing attempts, impersonation scams, and potential physical-security threats exploiting their leaked information.
- •Despite Trezor's repeated deletion requests, the customer data reportedly remained within ShipMonk's systems despite written assurances it would be removed.

Trezor has disclosed that an additional 67,000 customers in the United States were affected by a data breach involving its shipping provider ShipMonk, significantly expanding the number of users exposed in the incident. The new disclosure adds to concerns over the protection of customer information held by third-party service providers used by cryptocurrency companies.
The hardware wallet maker, operated by Czech-based SatoshiLabs, said on September 4 that the newly identified records belonged to U.S. customers who placed orders between November 2019 and August 2021. The exposed information included customer names, email addresses, phone numbers, shipping addresses, and order numbers.
With the latest disclosure, the total number of Trezor customers affected by the ShipMonk breach now stands at 80,689, of whom more than 67,000 are based in the United States.
The incident first came to light on August 13, when Trezor said ShipMonk, a third-party order-fulfillment provider, had notified the company of unauthorized access to systems containing customer information. At the time, the breach was reported to involve customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal whose orders had been fulfilled within the 90 days preceding August 8.
Earlier Disclosure Covered Nearly 14,000 Customers
Trezor's initial disclosure identified 11,742 customers whose names, email addresses, phone numbers, and shipping addresses had been exposed. A further 1,947 customers were identified as having partial information exposed, including their names, cities, and email addresses.
The newly disclosed records substantially increase the scale of the incident. Unlike the customers identified during the initial investigation, the additional U.S. users placed their orders over a much longer period, covering transactions made between November 2019 and August 2021.
Trezor said it had contacted all customers identified as affected by the breach. The company indicated that customers who did not receive a notification email should not be considered part of the newly identified group.
The company also emphasized that the breach did not compromise its hardware wallets or internal systems. According to Trezor, customer devices remain secure despite the exposure of personal information through its external shipping provider. Hardware wallets such as Trezor's store users' private keys offline, which is why a breach of order data does not by itself grant attackers access to funds.
Users Warned About Follow-Up Attacks
Although the company said the hardware devices and its own systems were not compromised, the exposure of names, contact information, and shipping addresses could create additional security risks for affected customers.
Trezor urged users to remain cautious about communications that appear to originate from the company or other trusted services. Potential threats include fraudulent emails, phone calls, and physical letters designed to exploit information obtained through the breach. The availability of shipping addresses also creates concerns beyond digital fraud, particularly for users who may own cryptocurrency hardware containing access to valuable digital assets.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…
— Trezor (@Trezor) September 4, 2026
Trezor has warned affected customers to remain alert for phishing attempts, impersonation scams, and potential physical-security threats following the exposure of their personal information. The concern is well grounded in precedent: in 2020, rival hardware wallet maker Ledger suffered a breach of its e-commerce database that exposed roughly one million customer email addresses and later fueled a wave of phishing attacks against customers, demonstrating how leaked order data can be weaponized long after the initial incident.
Data Deletion Claims Under Scrutiny
The breach has also raised questions about how customer records were handled by ShipMonk after Trezor requested their removal. Trezor said it had repeatedly sought and received written assurances from the shipping provider that the relevant customer information would be deleted.
However, the company said the data remained within ShipMonk's systems despite those assurances. The development has added another layer to the incident, shifting attention toward data retention practices and the safeguards applied by third-party service providers.
The episode highlights a broader challenge for hardware wallet companies, which may need to balance product security with the protection of customer information collected during purchases and deliveries. While the wallet devices themselves were not reported to have been compromised, exposed personal records can provide attackers with information that may be used in targeted social-engineering campaigns. It also raises questions customers may increasingly ask of crypto firms and their vendors: how long order data is retained, who has access to it, and whether deletion requests are actually verified rather than merely accepted on written assurance.
As the investigation continues, affected customers are likely to face increased attempts at impersonation and fraud. The expanding breach underscores the security risks associated with customer data held outside a cryptocurrency company's own infrastructure, even when the underlying hardware wallet systems remain uncompromised.