Trezor Breach Expands as 67K More Users Exposed
Trezor says another 67K US customers were affected by the ShipMonk data breach after historical order records from 2019 to 2021 were found still stored.
Trezor has significantly expanded the scope of the data breach involving its shipping provider ShipMonk, revealing that another 67K customers in the United States had their personal information exposed. The newly identified customers placed orders between November 2019 and August 2021, according to Trezor's September 4 update.
Exposed information includes customers' names, email addresses, phone numbers, shipping addresses and order numbers. The disclosure is an important development in an incident that Trezor originally reported in August.
Another 67,000 Trezor Customers Were Exposed
Trezor's initial disclosure came after ShipMonk informed the hardware wallet manufacturer on August 10 that an unauthorized party had accessed systems containing customer order information. At that stage, Trezor identified 11,742 customers whose names, email addresses, phone numbers and shipping addresses had been exposed.
Another 1,947 customers were initially identified as having more limited information exposed. That brought the known affected population to 13,689 customers.
The incident covered customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal, and EtherWorld previously examined how the exposed information could be used for targeted phishing and impersonation in Trezor ShipMonk Data Breach Exposes Customer Data. The latest investigation has now uncovered a much older dataset.
Trezor says another 67,000 customers in the United States who ordered between November 2019 and August 2021 were affected. Their exposed information includes full names, email addresses, phone numbers, shipping addresses and order numbers.
All newly identified affected customers have been contacted directly, according to the company. Trezor says users who did not receive an email regarding the expanded incident are not affected by the latest disclosure.
Why Trezor's Data-Retention Safeguard Failed
When the ShipMonk incident was first disclosed, Trezor highlighted its 90-day data-retention policy as an important reason the breach was relatively contained. The company said its fulfillment partners were required to delete or anonymize customer order information after the period necessary for delivery, returns, refunds or replacements.
The logic was straightforward. A shipping provider requires information such as a name, address, phone number and email while fulfilling an order.
Once the transaction and potential return period are finished, keeping that data creates additional risk without providing substantial operational value. Trezor's latest statement suggests that this protection did not work as expected.
The company says it had repeatedly requested deletion of the information and received written assurances from ShipMonk confirming that the data had been removed in line with contractual requirements. Trezor said it was "very disappointed" to discover that the records had instead remained in ShipMonk's systems.
Crypto has already seen numerous incidents where attackers did not need to compromise blockchain infrastructure directly. EtherWorld's coverage of crypto's human security problem has highlighted how attackers increasingly target users through trust, convincing interfaces and social engineering rather than attempting to defeat cryptography itself.
A database containing verified hardware wallet customers can potentially make those attacks considerably more convincing. The episode is also comparable to the recent SafePal data breach, where order information belonging to nearly 40,000 customers was exposed while private keys, seed phrases and wallet passwords remained secure.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
— Trezor (@Trezor) September 4, 2026
Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S
Trezor Wallets Remain Secure, But Users Still Face Risks
Trezor has emphasized that its own infrastructure was not compromised. The breach occurred at ShipMonk, and there is no indication from Trezor's disclosure that hardware wallets, private keys, recovery seeds or wallet backups were exposed.
That means users do not lose control of their cryptocurrency simply because their information appeared in the breached database. However, the exposed information creates a different form of risk.
EtherWorld previously reported how scammers sent physical letters containing malicious QR codes to hardware wallet users, directing victims to websites designed to steal their recovery phrases. On-chain investigator ZachXBT has also documented alleged operations using fake hardware wallet and exchange support calls to manipulate victims into giving attackers access to their assets.
The problem extends beyond hardware wallets. India's cybercrime authorities have warned about fake Trust Wallet verification pages and wallet-draining scams, while malicious websites impersonating popular wallet services remain a common method of obtaining recovery credentials.
EtherWorld's coverage of MetaMask-related cyber threats similarly highlighted how fake wallet applications, websites and malicious approvals can circumvent the security of the legitimate wallet by targeting its user. Other incidents show that even without stolen personal information, attackers continuously exploit user behaviour.
A recent address poisoning scam relied on transaction-history manipulation rather than compromising the victim's wallet, while an Ethereum phishing attack used malicious approval signatures to steal assets. For affected Trezor customers, this makes skepticism toward unsolicited communication especially important.
The Breach Exposes Crypto's Supply-Chain Security Problem
Companies such as Trezor can design devices so private keys remain isolated from internet-connected computers. Every additional provider can become another place where identifying information exists.
Crypto security discussions have traditionally focused heavily on smart contract exploits, compromised private keys and protocol vulnerabilities. EtherWorld's August security roundup showed just how diverse the attack surface has become, ranging from protocol accounting failures and price manipulation to wallet customer-data breaches.
Similarly, incidents involving older Ethereum wallets with compromised private keys demonstrate that long-lived security assumptions can eventually become vulnerabilities when information or credentials remain exposed for years. Trezor is now working on an Anonymous Delivery system designed to reduce how closely hardware wallet purchases are connected to users' identities and home addresses.
The company previously said the system would involve features such as locker pickup, neutral packaging, generic sender information and automatic deletion of shipping identifiers after delivery. The latest ShipMonk findings make that approach considerably more relevant.
Self-custody is ultimately designed to eliminate dependence on third parties for control over funds. But buying a physical self-custody device still creates dependencies before that wallet ever reaches the user.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- April 2026 Worst for DeFi: Over $635M Lost in Exploits
- Rhea Finance Exploit Drains $7.6M
- KelpDAO Exploit Triggers $290M Crisis Across DeFi
- DeFi Unites After KelpDAO $292M Hack
- How $900 Bought Control of an $8.5M DeFi Vault
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.