Key Takeaways
- ShipMonk security incident has expanded to affect 67,000 additional Trezor customers in the United States
- Compromised records span purchases made from November 2019 through August 2021
- Leaked information contains full names, contact details, residential addresses, and transaction identifiers
- ShipMonk provided written confirmation to Trezor that customer records had been purged from their systems
- Victims now face elevated risks including targeted phishing campaigns, fraudulent communications, and potential physical security threats
Hardware wallet manufacturer Trezor has disclosed that approximately 67,000 more American customers have been caught up in a security incident involving its logistics partner, ShipMonk. This revelation dramatically increases the scale beyond the initial 14,000 affected users Trezor acknowledged when it first publicized the breach on August 13.
On September 2, ShipMonk informed Trezor that additional compromised records had been discovered. These files pertain to customer transactions processed between November 2019 and August 2021.
The compromised information encompasses customer identities, electronic mail addresses, telephone numbers, delivery locations, and purchase identification numbers. Trezor has issued notification emails to all recently identified affected parties.
According to Trezor, its internal infrastructure remained secure throughout the incident. The company’s physical wallet devices continue operating safely, and no cryptocurrency funds were directly compromised.
The hardware wallet provider stated it had repeatedly requested ShipMonk to permanently erase outdated customer information. Trezor indicated it obtained written verification that the data deletion had been completed, consistent with contractual obligations and privacy protocols.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.
How Exposed Data Threatens Cryptocurrency Security
While no digital wallets suffered direct compromise, the stolen personal information creates significant vulnerability to sophisticated phishing campaigns. Bad actors can leverage names, physical locations, and email addresses to craft convincing impersonation attempts targeting Trezor users, ultimately seeking to extract their recovery seed phrases.
Recovery seed phrases represent complete control over cryptocurrency wallets. When users are manipulated into revealing these critical phrases, attackers gain unrestricted access to drain all digital assets.
Social engineering tactics and phishing schemes dominated cryptocurrency theft in early 2026. Blockchain security company Hacken documented that such fraud techniques were responsible for $306 million of the $482 million stolen industry-wide during the first quarter.
A notable July incident saw a single cryptocurrency holder lose nearly $1 million after being deceived into authorizing a malicious smart contract on the Ethereum blockchain.
Real-World Safety Implications Beyond Digital Threats
Users whose residential addresses were exposed confront dangers extending beyond internet-based fraud. Trezor cautioned affected individuals to remain vigilant for deceptive postal mail and telephone scams, in addition to electronic communications.
This situation parallels consequences from a 2020 security breach at competing hardware wallet company Ledger. That incident compromised over 270,000 customer records, with residential addresses subsequently leaked on underground forums. Ledger users continue reporting fraudulent calls and physical mailings years afterward.
Trezor maintained a data retention policy mandating fulfillment contractors delete or anonymize customer order information within 90 days following delivery. ShipMonk’s inability to honor this policy requirement forms the core of this security failure.
In January 2024, Trezor had previously alerted roughly 66,000 users who had contacted customer support since December 2021 about potential phishing exposure.
This most recent announcement means the aggregate total of Trezor customers involved in various data exposure events now reaches hundreds of thousands.
Trezor has not disclosed whether it intends to pursue legal remedies against ShipMonk.





