cleartext

Independent, sourced crypto news. No paid placements.

trezor

Trezor's ShipMonk breach balloons: 67,000 more customers exposed, records that should have been deleted

Trezor now says roughly 67,000 more U.S. customers had personal data exposed in a breach at its former shipping partner ShipMonk, far more than the ~14,000 it disclosed in August.

Hardware wallet maker Trezor said Friday that roughly 67,000 additional U.S. customers had personal information exposed in a data breach at its shipping provider, ShipMonk — a sharp expansion of an incident the company first disclosed on Aug. 13 as affecting fewer than 14,000 people, according to reporting by The Block.

Trezor said ShipMonk informed it on Sept. 2 that the breach was larger than previously understood, sweeping in order data from customers who placed orders between November 2019 and August 2021. The newly identified records include customers' names, emails, phone numbers, shipping addresses, and order numbers. Trezor said it has emailed everyone affected by the latest disclosure and warned them to watch for scam emails, fraudulent calls, letters, and potential physical-security risks.

The company stressed that its own systems were not compromised and that its hardware wallets remain secure. The exposure sits entirely with the third-party fulfillment provider.

Key facts

  • ~67,000 additional U.S. customers affected, per Trezor's Sept. 4 statement (The Block).
  • Original disclosure, Aug. 13: 11,742 customers had names, emails, phone numbers and shipping addresses exposed; another 1,947 had names, cities and emails leaked — about 13,689 total (The Block).
  • Exposed data: names, emails, phone numbers, shipping addresses, order numbers (Trezor, via The Block).
  • Timeframe of records: orders placed Nov. 2019–Aug. 2021 (Trezor).
  • ShipMonk notified Trezor of the larger scope on Sept. 2 (Trezor).
  • Trezor systems: not compromised; wallets unaffected (Trezor).
  • Precedent: a 2020 Ledger breach exposed data on 270,000+ customers, later published on a hacking forum (The Block).

The real-world read

The headline here isn't the breach — it's the walk-back. When Trezor first disclosed the incident in August, it reassured customers that the damage was contained by a policy requiring fulfillment partners to delete or anonymize order data 90 days after delivery. That reassurance has now collapsed: the freshly surfaced records go back to 2019, meaning data that was supposed to have been purged years ago was still sitting in ShipMonk's systems.

Trezor says it repeatedly asked ShipMonk to delete the data and received written confirmation, "in line with its contract," that it had been. "We are very disappointed that, despite receiving this confirmation, the data was not deleted," the company said. That framing puts the failure squarely on ShipMonk — a fair point, but also a self-interested one, and it doesn't change that Trezor's own August "it's limited" messaging didn't hold.

Two caveats worth stating plainly: this account rests on a single secondary report (The Block) relaying Trezor's statements; ShipMonk's own accounting hasn't been independently confirmed here, and there's no word on whether the total is final. And for hardware-wallet buyers, leaked home addresses are not just a phishing problem — the Ledger episode shows exposed customers fielding scam calls and physical letters years later.

This is news reporting, not financial or security advice.

Sources

  • The Block (Sameer, secondary reporting), "Trezor says ShipMonk breach affected another 67,000 customers," Sept. 4, 2026 — the sole account of the expanded disclosure, relaying Trezor's Friday statement and prior Aug. 13 figures, plus the 2020 Ledger comparison. The Block notes it is majority-owned by Foresight Ventures (crypto investor); no sponsorship of this item indicated.
  • Trezor (primary, quoted via The Block) — the affected-customer counts, data types, timeline, and the "very disappointed" statement. An interested party describing a breach at its own vendor; treat its framing accordingly.