Trezor said the ShipMonk data breach exposed 80,689 customers, far more than the 13,689 initially disclosed, after old order records that should have been deleted were found in the leaked dataset.
The hardware wallet maker announced the expanded scope on September 4 after learning on September 2 that the breach included order data from a prior partnership with ShipMonk between November 2019 and August 2021. That older dataset exposed roughly 67,000 additional U.S. customers whose names, email addresses, phone numbers, and shipping addresses were fully compromised.
The initial disclosure on August 13 covered 11,742 customers with full exposure of name, email, phone number, and shipping address, plus 1,947 with partial exposure of name, city, and email. Those records affected orders in the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026.
Combined with the newly acknowledged records from the earlier partnership period, the total number of affected customers now stands at 80,689. More than 67,000 of those are U.S.-based customers who ordered devices between late 2019 and mid-2021.
Retention policy failed
Trezor requires fulfillment partners to delete or anonymize order data 90 days after delivery. The company said it repeatedly requested and received written confirmation from ShipMonk that older records had been removed. They were not.
“This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses,” the company said in a post on X. “We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected.”
The root cause traces to a SQL injection vulnerability in Metabase, an open-source analytics platform that ShipMonk used to manage operations. Metabase notified ShipMonk on August 6 that an unauthorized party had used a software flaw to reach account and customer data. Later reporting identified the attack vector as a critical zero-day in Metabase that granted administrator access on compromised instances.
The 90-day retention policy was supposed to serve as a safety net. Even if ShipMonk’s systems were breached, the argument went, only recent orders and no older data would be exposed. The September 2 update shattered that assumption. ShipMonk had retained order data going back to 2019, years past the agreed deletion window.
Trezor had also received written assurances from ShipMonk that the older data was gone. The company said it “repeatedly requested and received written assurance from ShipMonk regarding the deletion of the data,” yet the records persisted in ShipMonk’s systems.
What was exposed
The leaked data includes names, email addresses, phone numbers, shipping addresses, and order numbers. Critically, the combination of a shipping address and a known hardware wallet purchase creates a profile that criminals can exploit in multiple ways.
Phishing is the most immediate risk. Scammers could impersonate Trezor, banks, or crypto exchanges via email, phone calls, or physical letters, pushing victims to reveal their wallet recovery seed. The shipping addresses add a physical dimension that email-only breaches lack. A bad actor now knows exactly which households hold crypto hardware wallets.
Trezor devices themselves remain secure. The company confirmed that no Trezor system, product, or service was compromised. Private keys and wallet backups were not leaked. The breach is limited to customer order and shipping information held by the fulfillment partner.
All affected customers were emailed from help@trezor.io. Anyone who did not receive a message was not part of the compromised dataset. Trezor advised recipients to treat any urgent request for personal data as hostile, verify claims only through official channels, and never type a wallet backup into a website or share it with anyone.
Anonymous delivery and ShipMonk future
Trezor is developing an Anonymous Delivery option that would use locker pickup, neutral packaging, a generic sender name, and automatic deletion of shipping identifiers after delivery. The company plans to launch the feature in Europe by September 2026 and in the U.S. by the end of the year.
The company has not announced whether it will drop ShipMonk as a fulfillment partner. Trezor previously said it would determine the partnership’s future after obtaining a complete picture of the incident. As of September 4, that decision remains unresolved even as the total number of affected customers approaches 80,000.
ShipMonk did not immediately respond to requests for comment about the scope of its breach or whether other customers of its fulfillment services were also affected.
Broader hardware wallet security concerns
The breach follows a series of hardware wallet security incidents in 2026 involving Safepal and Coldcard products. While those incidents involved device-level vulnerabilities, the Trezor case highlights a different attack surface entirely: the third-party logistics chain that sits between wallet makers and their customers.
For a product category built on the promise of cold storage and air-gapped security, the fact that customer shipping data was the weak link underscores a tension in the hardware wallet business model. Companies that sell physical devices need fulfillment partners to reach global customers, and those partners hold sensitive personal data that can undermine the very security the product is designed to provide.
The incident also raises questions about data retention practices across the crypto supply chain. If a logistics partner can retain years of order data past agreed deletion windows without the device maker knowing, the accountability gap extends well beyond any single vendor relationship.

discussion