Trezor Data Breach Widens as Another 67,000 US Customers…
Hardware wallet maker Trezor said another 67,000 US customers had their personal information exposed in a data breach at its shipping provider ShipMonk, significantly expanding the scope of an incident first disclosed last month.
The newly affected customers placed orders between November 2019 and August 2021, and their names, email addresses, phone numbers, shipping addresses and order numbers were exposed. Some of those records are almost seven years old, which pushes the incident far beyond the recent orders Trezor pointed to when it first described the breach.
Trezor said it received the latest update from ShipMonk two days ago and has emailed every affected customer directly. The disclosure follows its earlier report that around 13,689 customers had been affected by the ShipMonk breach, meaning the total number of exposed customers now runs to roughly 80,000.
Data Was Not Deleted
Trezor said the newly identified records remained in ShipMonk’s systems despite repeated requests to delete the information. The company said it had “repeatedly requested and received written assurance confirming the deletion of the data,” and described itself as “very disappointed” that the records survived despite those assurances.
The newly exposed records cover customers who ordered during a period that falls well outside Trezor’s stated 90-day data retention policy. Trezor said its contract and data policy required ShipMonk to delete or anonymize customer information once that retention period passed, and that the provider had confirmed in writing on more than one occasion that it had done so. The presence of the older orders in the leaked dataset shows the data was held long after it should have been cleared.
Trezor said customers who did not receive an email about the incident were not affected by the newly identified exposure. The company also stressed that the breach did not involve its own systems or hardware wallets. The exposed information consists of customer and order data held by ShipMonk, meaning the incident did not compromise Trezor devices, private keys or wallet backups.
Investor Takeaway
A third-party vendor retained data it was contractually required to delete, exposing weak oversight of fulfillment partners rather than any flaw in Trezor’s devices.
Trezor Warns of Phishing
The company warned affected customers to expect phishing attempts that draw on the exposed information. Scammers could use names, phone numbers, email addresses and shipping details to make fraudulent emails, calls or letters appear legitimate, and the presence of home addresses in the dataset raises the prospect of physical security risks as well.
The company urged customers never to share their wallet backup or enter it on a website, and to treat any unexpected contact that references a Trezor order with suspicion.
The warning comes after hardware wallet users have faced similar threats following customer data exposures. Ledger and Trezor customers were targeted with physical letters and other phishing attempts designed to obtain wallet recovery information in May, and Ledger confirmed a customer data exposure in January after a security incident involving its third-party provider Global-e.
Recent hardware wallet incidents have also highlighted risks that extend beyond customer databases. A Coldcard firmware flaw was linked to the theft of roughly 594 BTC from hundreds of wallets in July.
Trezor said it is working to introduce anonymous delivery to reduce the amount of customer information exposed when users order its products, aiming to make the service available in the European Union by September 2026 and in the US by the end of 2026.
Investor Takeaway
The leaked data hands attackers a target list of known wallet owners, putting customer trust and retention at risk in a market built on security.