Trezor says ShipMonk breach exposed about 80,700 customer records, not private keys
Trezor said on Sept. 4 that a data breach tied to logistics partner ShipMonk was much larger than first disclosed, with another 67,000 U.S. customers affected and the total reaching about 80,700 people. The leaked data includes names, email addresses, phone numbers, shipping addresses, and order numbers, while some customers had only partial information exposed. Trezor said its own systems, hardware wallets, private keys, wallet backups, seed backups, and device data were not affected.
The distinction matters because the breach did not expose wallet contents, but it did reveal who bought hardware wallets and where they live. That leaves customers open to targeted phishing, extortion, theft, and other real-world threats. Trezor said the newly identified records came from orders placed between November 2019 and August 2021 and should have been deleted. The company said it had repeatedly requested deletion under its contract and data policies and had received written confirmation, but the records remained in ShipMonk’s systems.
Trezor is now preparing an anonymous shipping option, including a dedicated checkout flow, locker pickup, neutral packaging, generic sender information, and automatic deletion of shipping identifiers after delivery. The feature is expected in the EU in September 2026 and in the U.S. by year-end, though it will not undo the leak of the roughly 80,000 records already exposed.