Trezor: Shipping Breach Exposed 80,689 Customers’ Details
Trezor attributes the incident to a breach at ShipMonk, its fulfillment and shipping partner, not to any compromise of its own infrastructure. The company’s cur...
Trezor says a breach at one of its shipping providers exposed the contact and delivery details of 80,689 customers, the hardware wallet maker disclosed in its official incident notice, stressing that its own systems, products and devices were not compromised.
TLDR Keypoints
- Trezor says a third-party shipping provider suffered a data breach.
- Customer contact and delivery details were exposed.
- 80,689 customers were affected, according to Trezor.
Trezor reports shipping-provider breach affecting 80,689 customers
Trezor attributes the incident to a breach at ShipMonk, its fulfillment and shipping partner, not to any compromise of its own infrastructure. The company’s current incident FAQ states that 80,689 customers are affected. For related coverage, see Trezor Announces Launch of Quantum-Ready Safe 7 Hardware Wallet.
Customers affected, according to Trezor
80,689
The current total is far larger than the original disclosure, published August 13, which counted 11,742 customers with full exposure and 1,947 with partial exposure. Those figures represent the original cohort, not the updated overall count.
In a September 4 update, Trezor said it was informed on September 2 that the breach included roughly 67,000 additional US customers, tied to orders placed between November 2019 and August 2021. Trezor said those historical records remained despite repeated requests and written assurances from ShipMonk confirming deletion.
We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
— Trezor Team, official incident update
Trezor describes a 90-day customer-order-data retention policy, which is why the surviving 2019 to 2021 records ran counter to what the company says it expected from its vendor. This is the second data-handling incident to touch Trezor customers, following its earlier disclosure of a breach at an email provider.
What customer information was exposed?
Contact and delivery details
Trezor says the exposed full-delivery dataset includes names, email addresses, phone numbers, shipping addresses, and order numbers. The company separately identifies the 1,947 partial-exposure records as name, city, and email, without a shipping address.
Crucially, Trezor says its systems, products and services were not compromised and its devices remain secure. This is a contact and order-data incident, not an established theft of wallet keys.
What the report does not establish
The disclosure does not indicate that passwords, payment information, private keys or recovery phrases were involved. Trezor says it notified affected customers directly and advises them never to share a wallet backup or enter it on a website.
Trezor warns that exposed contact details can enable phishing emails, fraudulent calls or letters, and potential physical-security risks. These are warned-about risks rather than verified consequences of this dataset. Rival Ledger has documented similar campaigns, including physical letters directing recipients to scan a QR code and enter recovery words, though those are separate Ledger incidents, not attacks tied to this Trezor data. The pattern echoes long-running concerns that Trezor hardware users have been targeted by phishing.
Similar exposure has hit competing brands this year, including a SafePal breach affecting more than 53,000 crypto owners, underscoring that vendor-side data handling is an industry-wide risk. Trezor has meanwhile continued product work, recently launching its quantum-ready Safe 7 wallet.
What remains unclear about the breach
Trezor attributes the surviving records and deletion assurances to ShipMonk, but no independent audit of the vendor’s conduct or the affected-customer dataset has been verified. Treat the counts and the deletion narrative as Trezor’s attributed statements.
No confirmed downstream theft, fraud or physical attack tied to these records has been established, and a widely circulated analysis claiming zero financial damage is, according to unconfirmed reports, not corroborated by the official notice. Reports attributing the original intrusion to a Metabase vulnerability also remain unverified.
Bitcoin traded at $77,159, down 0.32% over 24 hours, at the time of the research snapshot; there is no evidence linking the disclosure to price action. What to watch next: further Trezor FAQ updates, any ShipMonk statement, and whether affected customers report targeted phishing in the days ahead.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
More From Crypto News
Symbiosis Says It Recovered About 15 BTC After Bridge Exploit
Symbiosis said it recovered approximately 15 BTC and secured it in a team-controlled multisig, per CryptoSlate. The figure verifies the published attribution, n...
Senate to Hold First CLARITY Act Vote on Tuesday
The bill in focus is the Digital Asset Market Clarity Act, or CLARITY Act of 2025, which advanced through the House as H. R.
Schumer Calls Sunday Crypto Bill Caucus Ahead of Senate Vote
The account is unverified. A single source reported the caucus, and the underlying article was inaccessible, so no independent confirmation of who called the me...
Coinbase and Moov Plan Stablecoin Services for Local Banks
Coinbase describes Moov integrating its stablecoin infrastructure into Moov’s existing payments platform. The setup would use CDP Custodial Wallet accounts for...
BTCPay Warns Bots Probe Exposed LND Nodes for Admin Access
BTCPay Server has warned that automated bots are probing manually exposed LND nodes in an attempt to gain admin access, an activity the project says it observed...
Cosmos Hub Resumes Blocks; Ledger ATOM Issues Persist
Cosmos Hub has resumed block production after a multi-day disruption, but Ledger wallet issues persist for ATOM balances and transfers as of September 13, 2026....
Author
Akita Inu
Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.