Hardware wallet shipment shielded as retained delivery data escapes a warehouse network

Trezor Shipping Breach Expands by 67,000 Customers After Old Records Surface

September 5, 2026 7:09 pm Comments

Trezor says a breach at shipping provider ShipMonk exposed the personal information of another 67,000 U.S. customers, dramatically expanding an incident the hardware-wallet company first disclosed in August.

The newly identified group placed orders between November 2019 and August 2021. According to Trezor’s updated disclosure, the exposed fields include names, email addresses, phone numbers, shipping addresses and order numbers.

The update changes the practical scope of the breach. Trezor’s original August notice covered recent shipments in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, but the newly found records reach back nearly seven years.

Trezor says ShipMonk had provided written assurances that older customer data was being deleted in line with the companies’ contract and past communications. The later discovery means the retention protection Trezor described to customers did not operate as expected inside its fulfillment partner’s systems.

The manufacturer stressed that the parcel contents were not part of the leaked data and that its own systems were not breached. Even so, the combination of a customer’s identity, delivery address and order history can give a criminal enough context to build a highly personalized wallet-support scam.

That is especially sensitive information in crypto. A home address connected to a hardware-wallet purchase can give scammers more than a way to send a convincing email.

It can identify someone as a likely digital-asset holder and create risks involving fraudulent letters, targeted calls or physical intimidation.

Trezor said every newly affected customer was notified by email. People who did not receive that notice are not included in the expanded group identified by the provider.

The company’s warning is unusually concrete: expect criminals to use names, addresses and order details to make a contact look legitimate. Trezor says users should not share a wallet backup with anyone or enter it on a website, regardless of how convincing the request appears.

The central failure was not a compromise of Trezor’s wallets, firmware or recovery-seed system. Trezor said its devices remain secure.

The problem was retained fulfillment data: records the company says ShipMonk had repeatedly confirmed were deleted under its contractual and data-handling requirements.

Trezor says it is pushing toward an anonymous-delivery option so future buyers can reduce the personal information attached to a shipment. That would address the privacy weakness at the center of this incident without changing the security of the hardware wallet itself.

Protos reported that the first disclosed group included 13,689 customers and that ShipMonk notified Trezor on September 2 that the scope reached back into the companies’ earlier relationship. Combined with the new disclosure, the reported number of affected customers now exceeds 80,000.

The chronology matters. Trezor’s August notice said the incident affected recent buyers in seven countries and described the exposure as limited by a 90-day retention policy.

The discovery of older U.S. records undermines that assurance because the information apparently remained in the provider’s systems for years.

Trezor says affected customers were contacted directly. It is warning users to be alert for fake emails, calls and physical mail, and to never type a wallet backup into a website or share it with anyone.

Those instructions apply even if a message includes accurate personal details from an order.

The company also says it is working on anonymous delivery options and seeking an additional audit of ShipMonk. That response addresses the unusual privacy problem hardware-wallet sellers face: shipping a physical security product generally requires collecting the very identity and location data customers most want kept away from criminals.

For customers, the safest immediate response is procedural. Treat unsolicited wallet support as hostile, reach Trezor only through its official website, and never disclose a seed phrase.

Trezor says wallet systems were not affected. The expanded record count means the social-engineering threat is no longer confined to recent buyers.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.