Search

Trezor Says ShipMonk Breach Exposed Data of 67,000 More US Customers

Trezor Says ShipMonk Breach Exposed Data of 67,000 More US Customers

Hardware wallet manufacturer Trezor has disclosed that a data breach at its shipping provider, ShipMonk, affected significantly more customers than initially reported, with an additional 67,000 US customers now confirmed to have had their personal information exposed.

The newly identified customers placed Trezor orders between November 2019 and August 2021. According to Trezor, the exposed information includes customers’ full names, email addresses, phone numbers, shipping addresses and order numbers.

In an updated blog post, Trezor said all customers affected by the latest disclosure have been contacted directly by email. Customers who did not receive a notification are not affected by this additional exposure.

Data remained with ShipMonk despite deletion assurances

The company said it received the latest information from ShipMonk two days before its public disclosure and expressed particular concern over the fact that the data had apparently remained in the fulfillment provider’s systems despite previous assurances that it had been deleted.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” Trezor said, citing its contractual requirements, data policy and previous communications.

The company added that it was “very disappointed” that the data had not been deleted as previously confirmed.

The revelation follows Trezor’s initial disclosure of the breach on August 13, which involved 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed, alongside another 1,947 customers whose names, cities and email addresses were affected.

That initial incident concerned customers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who had received orders during the 90 days preceding August 8, 2026.

Trezor devices and systems were not compromised

Trezor stressed that the incident did not compromise its own systems or hardware wallets.

The primary concern for affected customers is instead the increased risk of targeted social engineering and phishing attacks. With names, addresses, phone numbers and information about previous Trezor purchases potentially available to attackers, criminals could use the data to make fraudulent communications appear more convincing.

Trezor warned customers to be particularly cautious about fake emails, phone calls and physical letters, as well as potential risks to their physical security.

The Czech company reiterated one of its most important security rules: customers should never share their wallet backup or enter it into a website, regardless of who requests it or how legitimate the request appears.

A legitimate Trezor representative will never need a customer’s recovery seed to restore, verify or secure a wallet.

Breach highlights risks beyond wallet security

The incident underscores a broader security issue facing hardware-wallet users: protecting the cryptographic keys controlling Bitcoin and other digital assets is only one part of the security equation.

A wallet can remain technically secure while information identifying its owner, including their name and physical address, becomes exposed. For high-value holders, such information can potentially create risks extending beyond conventional phishing attacks.

Trezor said it is working to introduce anonymous delivery as soon as possible, allowing customers to reduce the amount of personal information associated with future hardware-wallet purchases.

The company is continuing to investigate the incident and said further updates will be published through its official channels.

For customers concerned about the breach, Trezor recommends relying only on information published through its official website and communications channels and treating unsolicited requests involving wallet backups or recovery seeds as fraudulent.