Trezor said a breach at mailing partner ShipMonk affected another roughly 67,000 US users, expanding the incident well beyond what the hardware wallet maker first disclosed last month. The new figure brings the total number of affected users to more than 80,000.
Last month, Trezor said personal details belonging to 13,689 customers had been exposed after bad actors infiltrated ShipMonk’s systems. At the time, the company said a 90-day data policy followed by its partners meant older user data had been deleted, which it presented as a factor that helped limit the leak.
Trezor now says that policy was never enforced and that the data was never deleted.
Trezor says it repeatedly sought confirmation that data had been deleted
In a statement, Trezor said, 「Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.」
The company added, 「We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.」
Trezor said leaks like this can give criminals more information to tailor attacks against crypto users.
Initial notice covered only orders from the previous 90 days
Trezor told Protos it is too early to decide what action it will take in response to ShipMonk’s conduct. It also said it is working to arrange an additional audit of the mailing partner.
According to Trezor, ShipMonk first alerted the company on August 10 to a breach affecting orders from the prior 90 days. On September 2, ShipMonk then told Trezor the exposure in fact stretched back to 2019 and 2021.
Trezor said, 「Our understanding is that our cooperation from those years was overlooked when the original scope was established.」
Trezor says it had no reason to expect a broader leak
When Protos asked why it was ShipMonk that disclosed the additional scope, Trezor said it had no reason to expect further leaks because ShipMonk had repeatedly provided assurances.
Protos also noted that Trezor contacted the outlet last month to reveal details of the original leak, but did not do so this time. Asked why, Trezor said, 「The information is public and it is not behind anything. Our priority was reaching the people actually affected.」

