Trezor’s breach now covers more than 80,000 customers after a second disclosure. The 67,000 newly exposed U.S. buyers ordered between November 2019 and August 2021. ShipMonk had given Trezor
- Trezor’s breach now covers more than 80,000 customers after a second disclosure.
- The 67,000 newly exposed U.S. buyers ordered between November 2019 and August 2021.
- ShipMonk had given Trezor written confirmation that this data no longer existed.
- Recovery seeds and private keys were never accessible at any stage.
Trezor confirmed that roughly 67,000 additional U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers exposed through fulfillment partner ShipMonk, pushing the incident past 80,000 people worldwide. These records date from orders placed between November 2019 and August 2021 – a window Trezor believed had been wiped from ShipMonk’s systems years ago, based on written assurances the logistics provider had supplied on request.
A 90-day retention policy that a supplier quietly ignored for five years
Trezor holds fulfillment data for 90 days. That policy is the entire reason the company expected its August 13 disclosure to be the final word: 13,689 customers across seven countries, all of whom had ordered within the three months preceding August 8. ShipMonk had repeatedly certified in writing that the older 2019-2021 records were gone.
They were not. Half a decade of U.S. order data sat on a vendor’s servers, invisible to the company legally responsible for it, and became available the moment that vendor was breached. Trezor’s public response singled out ShipMonk’s failure to honour a contractual deletion commitment – a rare instance of a crypto firm naming its supplier rather than absorbing the reputational cost quietly.
DisclosureOrder windowAffectedFields exposedAug 13 Phase 190 days to Aug 8, 202613,68911,742 full record; 1,947 name, city, emailSep 4 Phase 2Nov 2019 – Aug 2021 (US)~67,000Name, email, phone, address, order numberCombined scope80,000+Seven countries, US majority
Security researchers attribute the ShipMonk intrusion to the ShinyHunters extortion group, which exploited an unpatched SQL injection flaw in Metabase, the business intelligence software ShipMonk used internally. SQL injection tricks a database into running queries it was never meant to run; because the flaw was a zero-day, no fix existed when the attack landed.
Trezor’s firmware, devices and seed generation were untouched, and no private key was ever within reach of the attackers. The intrusion happened several layers away from the hardware, inside the commerce plumbing that every physical product depends on.
Why a shipping address is worth more than an email dump
Anyone holding this dataset knows exactly who bought a hardware wallet, when, and where they live. That combination powers letters, calls and emails that cite a genuine order number and sound authentic enough to walk a victim toward disclosing a seed phrase.
Ledger’s customers have lived through the full arc of this. An API key vulnerability in 2020 exposed more than 270,000 names, emails, phone numbers and addresses, and once the file circulated on hacking forums, victims received fraudulent support calls and physical mail containing counterfeit replacement devices carrying seed-extraction malware. Trezor buyers now sit on the same starting line.
Three vendor failures in a single August
CertiK counted a 33% rise in targeted physical and cyber attacks on crypto holders during the first half of 2026. None of these breaches involved firmware or cryptography. Attackers unable to defeat a secure element are instead buying the customer list from whoever mails the box.
Anonymous delivery is the fix Trezor is now building
Trezor has emailed affected customers from [email protected] and says it is developing an anonymous delivery option that strips personal data from the shipment record itself. That shifts the defensive line: instead of trusting suppliers to delete data on schedule, the aim is to never hand it over. Whether competitors follow, and whether logistics providers can operate on minimal identifying data at scale, will determine if this remains a Trezor feature or becomes the industry’s default.
The post Trezor Data Breach Hits 67,000 More Customers, Total Tops 80,000 appeared first on ETHNews.