Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Trezor data breach expands to 80,700 customers after ShipMonk leak
00

Trezor data breach expands to 80,700 customers after ShipMonk leak

Sep 4, 2026

Hardware wallet manufacturer Trezor announced that a data breach at its shipping partner, ShipMonk, is far worse than initially reported. An additional 67,000 U.S. customers who ordered devices between November 2019 and August 2021 had their names, emails, phone numbers, and shipping addresses exposed, bringing the total affected to 80,700. Trezor expressed deep disappointment, revealing that ShipMonk had repeatedly provided false written assurances that this historical data had been deleted.

ShipMonk data breach expansion

  • ▪The newly exposed Trezor customer data involves orders placed by U.S. customers between November 2019 and August 2021, and includes names, emails, phone numbers, shipping addresses, and order numbers
  • ▪Trezor initially announced in August 2026 that the ShipMonk breach affected 13,689 customers, which included 11,742 customers with full exposure and 1,947 customers with partial exposure
  • ▪Trezor announced on September 4, 2026, that a data breach at its shipping partner ShipMonk affected an additional 67,000 U.S. customers, bringing the total compromised users to approximately 80,700
  • ▪ShipMonk notified Trezor on September 2, 2026, that the data breach was larger than previously disclosed, after having first notified Trezor of the initial leak on August 10, 2026

ShipMonk data retention failure

  • ▪Trezor stated that ShipMonk failed to delete customer data older than 90 days despite repeatedly providing written assurances that the data had been removed in accordance with their contract and data policy
  • ▪Trezor told Protos that ShipMonk's original scope assessment overlooked their cooperation from the years 2019 to 2021, which led to the delayed discovery of the older leaked data

Trezor customer security risks

  • ▪Trezor confirmed that its internal systems, devices, private keys, and wallet backups were not compromised, as the breach occurred entirely on ShipMonk's logistics end
  • ▪Trezor warned affected customers that the leak of names, physical addresses, and contact details exposes them to targeted phishing attempts via email, phone calls, physical mail, and potential physical safety risks

Trezor mitigation measures

  • ▪Trezor notified all affected customers via email regarding the expanded breach and advised them to never disclose their wallet backups or enter them onto websites
  • ▪Trezor announced that it is working to implement anonymous delivery options for future orders and is planning an additional audit of ShipMonk

Debatable claims

  • ▪Companies are responsible for data breaches at their third-party contractors
  • ▪Hardware wallet manufacturers should offer anonymous delivery options
  • ▪Physical security risks of hardware wallets outweigh their digital benefits

6 sources

The Block
Trezor says ShipMonk breach affected another 67,000 customers
View source article
Bloomberg
Trezor Crypto Wallet Data Breach Widens to 67,000 More US Customers
View source article
Cryptopolitan
Trezor data breach expands to 80,700 after ShipMonk leak
View source article
Bitcoin Magazine
Trezor Data Breach Worse Than Initially Reported
View source article
Protos
Trezor says mailing breach leaked 67K more users than first thought
View source article

Story comments

Loading comments…

Related entities

United States

Related Projects

Trezor

Topics

Bitcoin wallets & custodyCrypto hacksCrypto privacy & surveillance