Hardware wallet maker Trezor announced that a supply-chain data breach is far larger than previously disclosed.A security incident at third-party logistics vendor ShipMonk exposed the personal information of 67,000 additional U.S. customers, bringing the total number of compromised user records to over 80,000.
The expanded exposure was uncovered during an ongoing investigation into a third-party software flaw. However, the primary catalyst behind the sudden jump in numbers is not just a hacker’s exploit, but a glaring failure in vendor data retention policies.
Broken Promises on Data Deletion
When Trezor initially disclosed the breach in mid-August 2026, the company estimated that approximately 13,689 customers across seven countries were affected.At the time, Trezor pointed to its strict 90-day retention policy, which mandates that both Trezor and its fulfillment partners permanently delete customer names, delivery addresses, and contact numbers 90 days after fulfillment.
The latest disclosure reveals that ShipMonk failed to follow those contractual obligations.
Despite providing written assurances to Trezor that historical customer data had been erased, ShipMonk improperly retained order logs dating between November 2019 and August 2021. When attackers exploited a vulnerability in ShipMonk’s analytics software (Metabase), those legacy order files were exposed.
Trezor expressed deep disappointment over the discovery, stating that it had repeatedly requested and received confirmation from the logistics vendor that older logs were deleted.
What Information Was Leaked?
The leaked records include sensitive personal identifiers:
- Full legal names
- Physical shipping addresses
- Email addresses
- Phone numbers
- Specific order details and tracking numbers
What was NOT compromised: Trezor confirmed that its internal databases, firmware, hardware devices, seed phrases, and private keys remain completely secure.The breach took place entirely on ShipMonk’s external servers.
The Real Danger: Target on Customer Backs
While digital funds stored on Trezor devices remain safe, physical and social engineering risks for affected individuals have risen sharply.
Exposing a hardware wallet owner’s home address creates a direct correlation between an individual and self-custody crypto holdings. Security analysts warn that affected users should prepare for a wave of sophisticated cyber and real-world threats:
- Targeted Phishing Campaigns:Scammers will likely use order numbers and delivery details to craft highly believable fake emails, SMS messages, or calls posing as Trezor support.They may claim your wallet has been compromised and prompt you to enter your 12- or 24-word recovery seed phrase on a malicious site.
- Physical Security Concerns:Home address leaks introduce physical threat risks, including extortion letters, fraudulent postal hardware (fake replacement devices), or home invasion threats targeting high-net-worth holders.
How to Stay Safe
Trezor has already notified affected customers directly via email from help@trezor.io. If you bought a device through ShipMonk fulfillment during the affected windows, take these critical steps:
- Never Share Your Recovery Seed:No legitimate company—including Trezor—will ever ask for your seed phrase, backup key, or PIN.Never type your seed phrase into a computer keyboard or website.
- Ignore Unsolicited Replacement Hardware: If you receive an unexpected physical box claiming to be a “security update” replacement device, do not plug it into your computer.
- Verify Official Communications: Double-check sender domains and always navigate directly to official websites rather than clicking embedded email links.
To address long-term privacy concerns, Trezor plans to accelerate its Anonymous Delivery rollout, allowing users to pick up hardware orders at secure lockers without tying home addresses to crypto purchases.
