Another 67,000 Trezor Customers Were Exposed by Data ShipMonk Said It Had Deleted
Update, 4 September 2026: Trezor says the breach at fulfilment provider ShipMonk exposed data belonging to another approximately 67,000 US customers who ordered between November 2019 and August 2021. The newly identified records include names, email addresses, phone numbers, shipping addresses and order numbers.
The update overturns the reassuring part of Trezor’s original account. In August, the company said a contractual 90-day retention limit had constrained the incident to 13,689 recent customers. Trezor now says it repeatedly requested deletion throughout its relationship with ShipMonk and received written assurances that the data had been removed. According to Trezor, those older records were still present in ShipMonk’s systems.
Trezor’s own systems and devices were not compromised, and the company says customers’ hardware wallets remain secure. The risk sits outside the device: the exposed data connects identifiable people and physical addresses to purchases of cryptocurrency hardware wallets, making convincing phishing, fraudulent letters and physical targeting more plausible.
The breach now reaches years further back
ShipMonk informed Trezor of the incident on 10 August 2026. Trezor’s customer notice covered orders delivered between 10 May and 8 August in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
- 11,742 customers had their name, email address, phone number and shipping address exposed.
- 1,947 customers had a partial set consisting of name, city and email address exposed.
On 4 September, Trezor disclosed a much larger historical cohort: another approximately 67,000 US customers who ordered between November 2019 and August 2021. The company says their names, email addresses, phone numbers, shipping addresses and order numbers were exposed.
The September disclosure supersedes the earlier conclusion that the incident was limited to a 90-day order window. Any FAQ or summary that still describes only the recent-order cohort is now incomplete.
Trezor says wallet backups, PINs, account balances, payment-card data and device security were outside the affected fulfilment environment. It says all customers in the newly identified group were contacted directly.
The sensitive fact is the product relationship
A shipping address is ordinary commercial data until it is combined with a high-value product. The exposed records can tell an attacker that a specific person at a specific location purchased a device designed to protect cryptocurrency.
That does not prove the person currently holds digital assets or reveal their balance. It does make a tailored message more believable. An attacker can cite the product, delivery country and contact information while claiming that a wallet must be verified, replaced or recovered.
Trezor will never need a wallet backup to investigate a shipping incident. Any message asking for seed words, a PIN, a recovery check or a transaction approval should be treated as hostile.
A deletion promise is not a deletion control
The original disclosure made the 90-day retention policy look like the control that limited the damage. The new facts show that a contractual limit and written deletion assurance did not prove the supplier had actually removed historical customer data.
Trezor says it repeatedly requested deletion and received written confirmation from ShipMonk. That is Trezor’s account, and it does not establish why the records remained or who was responsible inside ShipMonk. It does establish an operational gap between the control documented on paper and the data still present when the supplier was breached.
For vendors handling sensitive purchases, supplier deletion needs evidence. Contracts should define deletion deadlines, include audit rights and require technical proof that production stores, exports, analytics systems and recoverable copies are covered. A policy cannot reduce breach exposure if retained copies survive outside the system being checked.
What affected customers should do
- Trust the device, not an unexpected message. Open Trezor Suite directly and use Trezor’s official support channels.
- Never disclose the wallet backup. No legitimate shipping, support or breach process requires the seed phrase.
- Expect precise phishing. The sender may know the recipient’s name, phone number, country, shipping address, order number and hardware-wallet purchase.
- Do not install replacement software from a link. Verify downloads through Trezor’s official site.
- Review physical privacy. Customers with higher risk may need to consider address exposure in their personal security planning.
- Preserve evidence. Report suspicious messages and retain headers, phone numbers and destination links without opening them.
The BlackTree view
Security boundaries do not end at the product. A hardware wallet can protect its cryptographic secrets correctly while fulfilment data exposes the identity and location of people who bought it.
The sharper lesson is that data minimisation must be verified across the supplier chain. Trezor says it asked for deletion and received written assurances, yet years of historical records were still exposed. For sensitive products, confirmation without technical evidence is not enough.
Sources
- Trezor official community statement: Follow up, please read, published 4 September 2026. Reddit does not provide a stable publication time on the public page.
- Trezor: Recent customer data exposed in shipping provider incident, initially published 13 August 2026. The page provides no publication time.


