Trezor says ShipMonk breach exposed about 80,700 customer records, not private keys

Trezor says ShipMonk breach exposed about 80,700 customer records, not private keys

N
News Editor
2026-09-05 08:07:58
Trezor said on Sept. 4 that a data breach tied to logistics partner ShipMonk was much larger than first disclosed, with another 67,000 U.S. customers affected and the total reaching about 80,700 people. The leaked data includes names, email addresses, phone numbers, shipping addresses, and order numbers, while some customers had only partial information exposed. Trezor said its own systems, hardware wallets, private keys, wallet backups, seed backups, and device data were not affected. The distinction matters because the breach did not expose wallet contents, but it did reveal who bought hardware wallets and where they live. That leaves customers open to targeted phishing, extortion, theft, and other real-world threats. Trezor said the newly identified records came from orders placed between November 2019 and August 2021 and should have been deleted. The company said it had repeatedly requested deletion under its contract and data policies and had received written confirmation, but the records remained in ShipMonk’s systems. Trezor is now preparing an anonymous shipping option, including a dedicated checkout flow, locker pickup, neutral packaging, generic sender information, and automatic deletion of shipping identifiers after delivery. The feature is expected in the EU in September 2026 and in the U.S. by year-end, though it will not undo the leak of the roughly 80,000 records already exposed.

Trezor said on Sept. 4 that the data breach involving logistics provider ShipMonk was larger than initially reported, with another 67,000 U.S. customers affected and the total rising to about 80,700.

According to the company’s account, 13,689 affected customers had already been disclosed on Aug. 13. The newly added 67,000 records came from orders placed between November 2019 and August 2021, bringing the cumulative figure to roughly 80,700.

The leaked information includes names, email addresses, phone numbers, shipping addresses, and order numbers. For some customers, the exposed fields were limited to name, city, and email address.

Trezor says wallets and private keys were not affected

In the same notice, Trezor said its own systems, hardware wallets, private keys, and wallet backups were not affected. It also said there was no sign that seed backups or device data had been exposed.

That means the breach revealed who bought a hardware wallet and where they live, not what was inside the wallet. As described in the report, that kind of leak does not let an attacker drain funds remotely, but it can make customers easier targets for extortion, theft, and tailored phishing attempts.

Older order records were supposed to be deleted

Trezor said the additional 67,000 records came from an earlier period in its relationship with ShipMonk. Under the contract and the company’s data policies, Trezor said it had repeatedly requested deletion of those records and had received written confirmation, yet the data remained in ShipMonk’s system.

Trezor said it was only informed on Sept. 2 that the older records were also part of the breach.

Similar incidents have hit other hardware wallet firms

The report noted that other hardware wallet companies have faced similar issues. SafePal disclosed on Aug. 16 that a vulnerability in an order-tracking plugin exposed personal data belonging to 39,798 customers.

It also pointed to Ledger’s 2020 customer address leak, which is still being used by criminal groups. According to the report, even in 2026, scammers were mailing physical letters while posing as official representatives and asking users to hand over their seed phrases. The article said leaked home addresses do not expire, which sets them apart from ordinary password leaks.

The main consequence is the so-called wrench attack

The report framed the fallout around “wrench attacks,” meaning physical attacks or home invasions targeting cryptocurrency holders.

CertiK counted 52 physical attacks against crypto holders worldwide in the first half of 2026, up from 39 in the same period of 2025, a 33% increase. Home invasion robberies have overtaken kidnappings as the most common method.

Chainalysis estimated losses from this type of attack at about $30 million this year.

Trezor is preparing anonymous shipping

To reduce identity exposure in delivery, Trezor said it is preparing an anonymous shipping option. The setup will include a dedicated checkout flow, pickup lockers, neutral packaging, generic sender information, and automatic deletion of shipping identifiers after delivery.

The report said the feature is expected to launch in the European Union in September 2026, with the U.S. rollout due by year-end. It applies to future orders only and does not reverse the leak of the roughly 80,000 records already exposed.

The report says the hardware wallet actually compromised this year was Coldcard

The article also drew a distinction between Trezor’s data leak and a separate compromise involving Coldcard.

According to the report, a firmware change made in March 2021 used a software pseudo-random function incorrectly, reducing seed entropy from 128 bits to about 40 bits and making brute-force attacks possible. Starting on July 30, 2026, more than 5,200 addresses were drained of 1,816 BTC, worth about $116 million.

An earlier summary section in the same piece described the Coldcard entropy flaw as dropping seed strength to 40 bits and said more than 5,200 addresses lost 1,816 BTC. A background note in the article separately stated that 1,596 BTC had been stolen.

What the article’s FAQ says

Can the Trezor leak directly lead to stolen bitcoin?

The answer given in the article is no, not directly. Trezor said its systems, hardware wallets, private keys, and wallet backups were not affected, and the exposed information was limited to names, phone numbers, email addresses, addresses, and order numbers. The risk, the article said, is that attackers may show up at a victim’s address or send carefully targeted phishing messages.

Have hardware wallets themselves ever been compromised?

The article’s answer is yes. It cited Coldcard and said a March 2021 firmware modification incorrectly used a software pseudo-random function, cutting seed entropy from 128 bits to about 40 bits and making the wallets vulnerable to brute-force recovery.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.