Powered by

Trezor Data Leak Spirals as 67,000 More US Buyers Get Exposed

Another day, another security alert. Hardware wallet manufacturer Trezor says a breach involving shipping partner Shipmonk exposed the personal information of roughly 67,000 additional U.S. customers after records that Trezor says should have been deleted instead remained tucked away in the vendor’s systems.

WRITTEN BY
SHARE
Trezor Data Leak Spirals as 67,000 More US Buyers Get Exposed

Key Takeaways

  • Trezor added 67,000 U.S. customers to its Shipmonk breach on Sept. 4.
  • Trezor’s leak now covers roughly 80,000 people, including home addresses.
  • Trezor targets U.S. Anonymous Delivery by the end of 2026.

The newly identified records cover U.S. orders placed between November 2019 and August 2021 and expand an incident that had already affected 13,689 more recent customers across several countries. Altogether, the breach now involves roughly 80,000 people, although Trezor’s systems, devices, private keys, and wallet backups were not compromised.

Trezor Finds 67,000 More U.S. Customers in the Breach

Following the last disclosure, Trezor said it learned Sept. 2 that the Shipmonk breach was larger than initially reported. The older records contain customers’ names, email addresses, phone numbers, shipping addresses, and order numbers, giving attackers information that could make scams far more convincing.

Trezor security alert via X on Sept. 4, 2026, screenshot.
Image source: Trezor security alert via X on Sept. 4, 2026.

The discovery is particularly troubling because Trezor says it repeatedly asked Shipmonk to delete the information and received written confirmation that it had been removed. Trezor said the assurances were consistent with its contract, data policy and previous communications with the fulfillment provider.

That also raises questions about Trezor’s advertised 90-day data retention policy with fulfillment partners. The newly discovered records date back years, showing that the policy was not enforced for the affected 2019-2021 U.S. customers.

Leaked Addresses Push the Threat Beyond Email Phishing

The information exposed does not allow an attacker to remotely access a Trezor wallet. Private keys and seed phrases, the secret recovery words used to control a crypto wallet, were not part of the breach.

But the type of information exposed creates a different problem. Trezor warned that leaked phone numbers and home addresses could potentially put affected customers at physical risk, while real order numbers and contact details could help scammers impersonate the company more convincingly.

The breach originated outside Trezor. Attackers exploited a previously unknown SQL-injection vulnerability in Metabase, an analytics platform used by Shipmonk. Metabase notified Shipmonk around Aug. 6, patched the vulnerability and invalidated sessions, while Shipmonk later explained that it secured its systems.

Third-Party Data Failures Put Hardware Wallet Buyers at Risk

The incident follows other third-party exposures involving Trezor customers. About 106,856 customers were affected in a 2022 incident, while a compromised support portal in 2024 exposed as many as 66,000 names and email addresses. In each case, the hardware wallets themselves were not remotely compromised.

That distinction matters for customers deciding how to respond. Trezor warns that nobody from the company will ask for a wallet backup, meaning customers should never enter their seed phrase into a website or hand it over to someone claiming to provide support.

Trezor Pushes Anonymous Delivery as Shipmonk’s Future Hangs

Trezor is now promoting an Anonymous Delivery system designed to reduce the amount of customer information retained during hardware wallet purchases. The system includes locker pickup, neutral packaging, a generic sender, and automatic deletion of shipping identifiers after delivery, with a European launch targeted for September and a U.S. rollout planned by the end of 2026.

For now, Trezor has not announced plans to drop Shipmonk. The company previously said it would determine the partnership’s future after obtaining a complete picture of the incident, leaving that decision unresolved even as the known number of affected customers approaches 80,000. The issue follows a number of scary hardware wallet incidents that have happened in 2026, associated with Safepal and Coldcard wallets.