Trezor's ShipMonk Breach Adds 67,000 US Customers From Old Orders

Trezor said on Friday that a breach at its shipping partner reached about 67,000 more US customers than the company first counted. The new records cover orders placed between November 2019 and August 2021. Trezor's contract with the fulfillment firm ShipMonk called for order data to be deleted or anonymized 90 days after each delivery, and the company says it asked repeatedly for that to be done. The data was still there. Names, home addresses, phone numbers and email addresses went out; wallet backups and private keys did not.
Two windows, not one
Trezor's own incident page splits the affected orders into two groups. The first count, published on 13 August, covered 13,689 customers in seven countries whose orders shipped between 10 May and 8 August 2026. Of those, 11,742 had a full set of details exposed and 1,947 had only a name, a city and an email. The 67,000 announced on Friday sit in a separate and much older window. The Block and CyberInsider both put the running total at about 80,689, and both attach the 2019 and 2021 dates to the incident as a whole without separating the two groups. Trezor's page separates them. The accounts do not reconcile, and the company's own page is the later of the two.
The rule that was supposed to erase this
Ninety days is the number the case turns on. Trezor requires partners to delete or anonymize order data 90 days after delivery, a rule its page says covers the whole life of an order, including returns, refunds and replacements. Records from 2021 were still readable in 2026. Trezor says it asked ShipMonk to confirm deletion throughout the relationship and received written assurance each time.
"We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems," Trezor said in a statement carried by The Block on Friday.
Retention policy at a hardware-wallet maker has been contested before. Coinkite, which builds the Coldcard, suspended its own deletion schedule in August, citing preservation duties from anticipated legal proceedings.
How the data got out
The route is reported but confirmed by neither company. Cybersecurity News and Bitcoin.com News both point at Metabase, the analytics software ShipMonk ran, and Cybersecurity News quotes an attribution to a SQL injection flaw that gave administrator access to compromised installations. SQL injection is an old class of attack in which an input field is used to run database commands. Trezor's page does not name the mechanism, and no account reviewed for this piece carries a statement from ShipMonk. On the timeline the reports agree: Metabase alerted ShipMonk on 6 August, ShipMonk found the breach on 10 August, Trezor disclosed on 13 August, and ShipMonk told Trezor the count was larger on 2 September. A broker's records went a similar way last month, when a data-analysis system at Israel's Bits of Gold exposed up to 250,000 people.
What changes for the people on the list
Nothing about the coins. Trezor's position is that its systems were not touched and the devices are secure, and no account reviewed here disputes it. The exposure is the combination of a full name, a phone number and a home address, held against a list of people known to own hardware wallets. Trezor told affected customers to treat urgent requests as suspicious, to verify through official channels only, and never to type a wallet backup into a website. It is planning an anonymous delivery option with locker pickup, neutral packaging and automatic deletion of shipping identifiers, due in the EU this month and in the US by the end of the year.
What happens to the relationship is not on the record. No outlet has published a ShipMonk statement, Trezor has not said whether it will keep the firm, and nobody has said how many of the 67,000 have been contacted so far. That last count is the one worth waiting for.
Read also: Injective's npm SDK Was Backdoored to Steal Seed Phrases