‹ BackNewsShipMonk

ShipMonk

Trezor says breach at email marketing provider led to phishing emails sent to 347,000 customers
Trezor says third-party email provider was breached in phishing campaign using fake STM32 flaw alert
Trezor says breach was larger than first disclosed, with another 67,000 U.S. customers exposed
Trezor
2026-09-05 08:07:58

Trezor says ShipMonk breach exposed about 80,700 customer records, not private keys

Trezor said on Sept. 4 that a data breach tied to logistics partner ShipMonk was much larger than first disclosed, with another 67,000 U.S. customers affected and the total reaching about 80,700 people. The leaked data includes names, email addresses, phone numbers, shipping addresses, and order numbers, while some customers had only partial information exposed. Trezor said its own systems, hardware wallets, private keys, wallet backups, seed backups, and device data were not affected. The distinction matters because the breach did not expose wallet contents, but it did reveal who bought hardware wallets and where they live. That leaves customers open to targeted phishing, extortion, theft, and other real-world threats. Trezor said the newly identified records came from orders placed between November 2019 and August 2021 and should have been deleted. The company said it had repeatedly requested deletion under its contract and data policies and had received written confirmation, but the records remained in ShipMonk’s systems. Trezor is now preparing an anonymous shipping option, including a dedicated checkout flow, locker pickup, neutral packaging, generic sender information, and automatic deletion of shipping identifiers after delivery. The feature is expected in the EU in September 2026 and in the U.S. by year-end, though it will not undo the leak of the roughly 80,000 records already exposed.

870
Trezor says ShipMonk breach exposed about 80,700 customer records, not private keys
Trezor says ShipMonk breach exposed 67,000 more US users, taking total above 80,000
Trezor Updates ShipMonk Breach: 67,000 More US Users Exposed
Trezor
2026-08-14 11:06:07

Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny

Trezor disclosed on Aug. 13 that its logistics partner ShipMonk suffered unauthorized access to a system holding customer information, affecting 13,689 people. The exposed data fell into two groups: 11,742 customers had their full names, email addresses, phone numbers and full shipping addresses exposed, while 1,947 had their names, city and email addresses exposed. Trezor said its own systems, products and services were not compromised, and that hardware wallets, private keys and wallet backups were not part of the incident. The disclosure came two days after a user posted that the outer label on a domestically shipped Trezor Safe 3 package explicitly read "Trezor Safe 3 Bitcoin Only" instead of a generic product description. There is no confirmed direct link between the shipping-label complaint and the ShipMonk breach, but together they highlight the same problem: a hardware wallet may protect private keys, while purchase, fulfillment and delivery processes can still connect the device to a real-world identity. The episode has also fed a broader debate over hardware-wallet risk. Recent incidents involving Trezor, Coldcard and Ledger did not stem from the same failure point. Some relate to device or firmware security, while others involve third-party commerce, logistics or packaging exposure. For affected users, the most immediate concern is targeted phishing and social-engineering attempts that use real names, addresses, order details and device information to appear credible.

510
Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny
Trezor says ShipMonk breach exposed order data of 13,689 customers