United Statescountry
DevelopingSecurity

Trezor breach affects additional 67,000 US customers as old shipping logs resurface

Trezor expanded its breach disclosure to 67,000 additional US customers after finding years-old order records at ShipMonk that should have been deleted.

Why it matters

The breach highlights risks for hardware wallet customers when third-party vendors fail to honor data retention policies. The leaked data links identifiable individuals with physical shipping addresses and hardware wallet purchases, creating potential for targeted phishing and physical security threats beyond conventional email leaks.

Where the sources disagree

Whether the two groups overlap

Approximately 80,689 total (roughly 13,689 original plus 67,000 new)

CryptoSlate

About 67,000 newly exposed (combined figure not stated)

The Daily Hodl

CryptoSlate notes Trezor has not published underlying data showing whether the original 13,689 and the new 67,000 overlap, while The Daily Hodl does not address this question.

Key facts

Trezor disclosed an additional 67,000 US customers exposed in the ShipMonk breach

67,000 customersDisputed figureReported by CryptoSlate

The original August 13 disclosure affected 13,689 people

13,689 peopleDisputed figureReported by CryptoSlate

ShipMonk notified Trezor on September 2 that order records from November 2019 through August 2021 remained in its systems

Reported by CryptoSlate

Trezor sent email notices to affected customers on September 4

Reported by CryptoSlate

Exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers

Reported by CryptoSlate

Trezor had received repeated written assurances from ShipMonk confirming data deletion

Reported by CryptoSlate

Trezor's own systems and hardware wallets were not compromised

Reported by The Daily Hodl

What happened

Hardware wallet manufacturer Trezor expanded its disclosure of a data breach at logistics provider ShipMonk, adding approximately 67,000 US customers to the affected count. The newly discovered records covered orders from November 2019 through August 2021 and included names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said it had received repeated written assurances from ShipMonk that older customer data had been deleted, but the company expressed disappointment that those assurances proved inaccurate. The original August 13 disclosure had counted 13,689 affected individuals, implying a combined total of roughly 80,689, though Trezor has not issued a single combined figure and it remains unclear whether the two groups overlap. ShipMonk notified Trezor of the retained records on September 2, and Trezor sent email notices to affected customers on September 4. The company emphasized that its own systems and hardware wallets were not compromised in the incident.

How the story developed

  1. Update

    Trezor first disclosed the breach

    The company reported 11,742 customers with full exposure and 1,947 with partial exposure, saying older order data had already been deleted

    CryptoSlate

  2. Correction

    Trezor clarified the original disclosure

    An August 14 clarification acknowledged some records remained

    CryptoSlate

  3. Update

    ShipMonk notified Trezor that old records were found

    Order records from November 2019 through August 2021 remained in ShipMonk systems despite deletion assurances

    CryptoSlate

  4. Official statement

    Trezor sent breach notifications to affected customers

    Email notices sent via privacy@trezor.io; those not contacted are not part of the expanded breach

    CryptoSlate

  5. First report

    First report by CryptoSlate

    Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found

    CryptoSlate

How coverage built up

Independent sources over time, counted the way the consensus panel counts them: a republication of a wire story does not move the line.

5 Sept, 19:002 independent sources5 Sept, 21:10
  • 5 Sept 2026, 19:00 UTC: CryptoSlate 1 independent source, 1 reports
  • 5 Sept 2026, 21:10 UTC: The Daily Hodl 2 independent sources, 2 reports

Affected entities

Original sources

PublisherReportRolePublished
CryptoSlate
Crypto media
Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are foundOriginal
The Daily Hodl
Crypto media
Trezor Warns 67,000 U.S. Customers As Data Breach Discovery ExpandsSyndicated