Key Points
- Hardware wallet provider Trezor disclosed that 67,000 more US-based customers were impacted by a data breach at shipping partner ShipMonk
- The compromised records span purchases made from November 2019 through August 2021
- Leaked information contains full names, email contacts, telephone numbers, delivery addresses, and purchase references
- ShipMonk provided written confirmation to Trezor that customer information had been purged from systems
- Users now face elevated risks including targeted phishing campaigns, fraudulent communications, and potential compromise of cryptocurrency assets
Hardware cryptocurrency wallet manufacturer Trezor has disclosed that approximately 67,000 more customers in the United States had sensitive information compromised following a security incident at ShipMonk, its third-party logistics provider. This revelation significantly expands the scope beyond the initial 14,000 affected users Trezor acknowledged when it first announced the breach on August 13.
On September 2, ShipMonk informed Trezor that additional customer records had been discovered in the compromised dataset. The newly identified records correspond to transactions processed during the timeframe spanning November 2019 to August 2021.
The compromised information encompasses customer full names, email addresses, contact phone numbers, physical shipping addresses, and transaction order numbers. Trezor has initiated direct email communications to all newly identified victims to alert them of the exposure.
Trezor emphasized that its internal infrastructure remained uncompromised throughout this incident. The security integrity of its hardware wallet devices remains intact, and no cryptocurrency funds were directly accessed by threat actors.
According to Trezor, the company had repeatedly requested ShipMonk to permanently erase historical customer information from their systems. The wallet provider stated it had obtained written assurances confirming the data deletion had been executed in accordance with contractual obligations and data retention protocols.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.
The Threat to Cryptocurrency Security
While the breach did not result in direct wallet compromise, the exposure of personal customer information creates significant vulnerabilities for sophisticated phishing operations. Malicious actors can leverage the stolen names, addresses, and contact details to craft convincing fraudulent communications impersonating Trezor, attempting to deceive users into revealing their recovery seed phrases.
Recovery seed phrases represent the master key to cryptocurrency wallets. Once compromised, these phrases grant complete control over wallet contents, enabling attackers to drain all stored digital assets.
Social engineering and phishing campaigns represented the primary vector for cryptocurrency theft during the first quarter of 2026. Blockchain security monitoring firm Hacken reported that these attack methods were responsible for $306 million in losses out of the total $482 million stolen across the cryptocurrency ecosystem during that three-month period.
In one notable incident last July, a cryptocurrency holder suffered losses approaching $1 million after being manipulated into authorizing a malicious smart contract transaction on the Ethereum blockchain.
Real-World Safety Implications
Users whose residential addresses were exposed face threats extending beyond digital scams. Trezor specifically cautioned affected individuals to remain vigilant for fraudulent postal mail and telephone-based social engineering attempts, in addition to email phishing.
This situation parallels the aftermath of a 2020 security breach at competing hardware wallet manufacturer Ledger. That incident compromised data belonging to over 270,000 customers, with residential addresses subsequently leaked on underground forums. Ledger customers have continued reporting targeted scam phone calls and fraudulent physical mailings in the years following that breach.
Trezor maintained a data retention policy requiring fulfillment partners to permanently delete or anonymize customer order information within 90 days following successful delivery. ShipMonk’s apparent failure to comply with this requirement forms the core issue underlying this security incident.
Previously, in January 2024, Trezor had already notified approximately 66,000 users who had contacted customer support since December 2021 that their information was potentially at risk of being exploited in phishing campaigns.
With this latest revelation, the cumulative total of Trezor customers affected by various data exposure incidents over recent years now reaches several hundred thousand individuals.
Trezor has not publicly stated whether it intends to pursue legal remedies against ShipMonk for the data retention failure.


