BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

ShipMonk Breach Exposes 67,000 More Trezor Wallet Users Despite Deletion Assurances

Key Points Hardware wallet manufacturer Trezor reveals that 67,000 more US-based customers were impacted by a data breach at shipping partner ShipMonk The latest disclosure involves customer

AnonymousCryptoCompass newsroom
September 5, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

Key Points

  • Hardware wallet manufacturer Trezor reveals that 67,000 more US-based customers were impacted by a data breach at shipping partner ShipMonk
  • The latest disclosure involves customer orders processed from November 2019 through August 2021
  • Compromised information encompasses full names, email contacts, telephone numbers, physical mailing addresses, and purchase identifiers
  • The company maintains it received documented confirmation from ShipMonk that customer records had been permanently erased
  • Impacted users now face heightened risks including targeted phishing campaigns, fraudulent phone contact, deceptive postal mail, and potential cryptocurrency theft

The hardware wallet manufacturer Trezor has officially disclosed that approximately 67,000 additional United States customers have had sensitive personal information compromised through a security incident at ShipMonk, its third-party logistics provider. This revelation significantly expands the scope of the breach beyond the initial estimate of roughly 14,000 affected users that the company announced when it first reported the incident on August 13.

On September 2, ShipMonk notified Trezor that additional customer records had been discovered in their systems. These newly identified records correspond to purchases made during the timeframe spanning November 2019 to August 2021.

The compromised information encompasses a range of personally identifiable details: complete customer names, electronic mail addresses, contact phone numbers, residential and commercial shipping locations, along with transaction identification numbers. Trezor has since reached out via email to all newly identified victims to alert them of the exposure.

The wallet manufacturer emphasizes that its internal infrastructure remained untouched during this incident. The security integrity of its hardware wallet devices continues intact, and no cryptocurrency funds stored within user wallets were directly compromised or accessed.

According to the company’s statement, Trezor had repeatedly requested that ShipMonk purge legacy customer information from their databases. The company states it obtained written verification confirming the data elimination had been completed, consistent with their service agreement and privacy protocols.

“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

Elevated Threat Landscape for Cryptocurrency Assets

While the breach did not result in direct wallet compromise, the exposure of detailed personal records creates significant vulnerability to sophisticated phishing operations. Malicious actors can leverage the combination of names, physical locations, and email contacts to craft convincing impersonation schemes targeting Trezor users, attempting to extract their recovery seed phrases.

Recovery seed phrases represent the master key to cryptocurrency wallets. Should an individual be manipulated into disclosing this critical information, attackers gain unrestricted control over the wallet contents, resulting in total asset loss.

Social engineering tactics and phishing schemes emerged as the predominant attack vectors in the cryptocurrency sector during early 2026. Blockchain security analytics firm Hacken documented that these deceptive techniques were responsible for $306 million in losses—representing nearly two-thirds of the $482 million stolen industry-wide throughout the first quarter.

A particularly devastating incident occurred in July when a single cryptocurrency holder suffered losses approaching $1 million after being deceived into authorizing a malicious smart contract interaction on the Ethereum blockchain.

Real-World Security Vulnerabilities

Users whose residential addresses were exposed face threats extending beyond the digital realm. Trezor specifically cautioned affected individuals to remain vigilant for suspicious physical correspondence and fraudulent telephone contacts, in addition to email-based scams.

This situation bears striking resemblance to the aftermath of a 2020 security breach at Ledger, a competing hardware wallet manufacturer. That incident compromised data belonging to more than 270,000 customers, with home addresses subsequently released on underground forums. Years later, Ledger customers continue reporting persistent scam phone calls and deceptive physical mailings.

Trezor had implemented a data retention policy mandating that fulfillment partners either permanently delete or fully anonymize customer order information within 90 days following successful delivery. ShipMonk’s apparent failure to honor this contractual obligation represents the fundamental cause of this expanded breach.

Previously, in January 2024, Trezor had already issued warnings to approximately 66,000 individuals who had initiated contact with its customer support infrastructure since December 2021, alerting them to potential phishing exposure.

With this most recent announcement, the aggregate total of Trezor customers affected by various data exposure events has now escalated into the hundreds of thousands.

The company has not publicly disclosed whether it intends to pursue legal recourse against ShipMonk for the security failure and contractual breach.

The post ShipMonk Breach Exposes 67,000 More Trezor Wallet Users Despite Deletion Assurances appeared first on Blockonomi.