Trezor says approximately 67,000 additional U.S. customers were affected by the data breach at shipping provider ShipMonk, pushing the total number of exposed hardware wallet customers to more than 80,000.
The newly identified records are significantly older than those disclosed when Trezor initially confirmed the ShipMonk breach affecting 13,689 customers in August. They belong to U.S. customers who ordered Trezor products between November 2019 and August 2021.
Exposed information includes names, email addresses, phone numbers, shipping addresses and order numbers. Trezor said its own infrastructure was not compromised and that its hardware wallets, services and customer cryptocurrency remain secure.
The expanded disclosure also raises a significant data-retention issue. Trezor says ShipMonk had repeatedly provided written assurances that the older customer information had been deleted in accordance with contractual requirements and Trezor’s data policy.
67,000 older customer records remained at ShipMonk
ShipMonk informed Trezor on Sept. 2 that the scope of the August breach was larger than previously known. Trezor disclosed the expanded impact on Sept. 4, confirming that approximately 67,000 additional U.S. customers were affected.
The original incident affected 13,689 customers, primarily involving orders fulfilled between May 10 and Aug. 8, 2026 across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
The newly identified group adds approximately 67,000 U.S. customers whose orders date from November 2019 through August 2021. Combined, the disclosures bring the known number of affected Trezor customers to approximately 80,689.
The additional records contain full customer details required for fulfillment, including names, email addresses, phone numbers, shipping addresses and order numbers.
No wallet backups, recovery seeds or private keys were exposed, according to Trezor.
Data was supposed to have been deleted
The age of the newly exposed records has become one of the most significant aspects of the incident.
Trezor previously said its fulfillment partners were required to delete or anonymize customer order information after it was no longer needed. The company now says it repeatedly requested and received written confirmation from ShipMonk that the historical information had been deleted.
The discovery of approximately 67,000 records from orders placed as far back as 2019 shows that the information remained in ShipMonk’s systems when the breach occurred years later.
Trezor said it was disappointed to learn that the data had not been deleted despite those assurances.
The retention failure substantially increased the impact of the breach. Instead of exposing information associated primarily with recent shipments, the incident now affects a much larger population of customers from Trezor’s previous relationship with ShipMonk.
Metabase exploitation linked to the ShipMonk incident
Additional details have also emerged about the attack that exposed the ShipMonk data.
Breach notifications sent to affected customers reportedly state that attackers exploited a vulnerability in third-party analytics platform Metabase to access information held by ShipMonk.
Metabase disclosed in August that attackers had exploited a critical SQL injection zero-day against customer instances, allowing unauthorized parties to gain administrator access and steal data. Other organizations affected during the broader Metabase campaign include laptop manufacturer Framework and online form platform Tally.
ShipMonk has also reportedly received extortion communications from ShinyHunters. However, neither Trezor nor ShipMonk has publicly attributed the breach to the group, so ShinyHunters’ role in the incident remains unconfirmed.
Home addresses create added risk for hardware wallet owners
The exposure carries additional security implications because the leaked shipping records identify individuals who purchased cryptocurrency hardware wallets.
Names, email addresses, phone numbers and order information can support targeted phishing and impersonation attempts. Shipping addresses introduce a physical security concern by potentially linking cryptocurrency users to their residences.
Trezor warned affected customers that the information could be used for fraudulent emails, calls or letters and said individuals may also face physical security risks.
The company emphasized that it will never request a customer’s wallet backup or recovery seed. Possession of the exposed ShipMonk information alone does not allow an attacker to access funds stored using a Trezor wallet.
Trezor says its systems remain secure
Trezor said the incident remains isolated to its shipping provider and did not compromise its own infrastructure or services.
The company has contacted customers affected by the expanded disclosure directly. The newly identified group consists of U.S. customers whose historical ShipMonk fulfillment records were retained despite the expected deletion of that information.
The expanded scope brings the incident from fewer than 14,000 known victims in August to more than 80,000 customers and shifts part of the focus from the original intrusion to why years-old customer records remained available to be stolen.
ShipMonk had not issued a separate public statement addressing the expanded Trezor disclosure at time of publication.











