Trezor said on Friday that a hack at its shipping company exposed the personal details of about 67,000 more US customers than first reported.
The extra records date back to orders placed between November 2019 and August 2021. They include names, email addresses, phone numbers, home addresses and order numbers, according to The Block.
That takes the total number of people affected to roughly 80,700. Trezor originally said 13,689 customers were caught up in the breach when it disclosed the incident on 13 August.
Trezor’s own systems were not hacked. Devices, private keys and wallet backups are all safe.
These records were meant to be gone
Here is what makes this worse than a normal breach.
Trezor deletes customer order details 90 days after delivery. That window covers the delivery itself plus any returns or refunds, after which the company says it has no reason to keep an address or phone number.
Records from 2019 to 2021 should have been wiped years ago.
Trezor said it asked ShipMonk repeatedly to delete them and got written confirmation that the job was done, as required by their contract.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” the company said.
The policy was right. The contract was right. The paperwork said the records were gone. They were not, and Trezor had no way of checking.
What happened at ShipMonk
ShipMonk told Trezor about the break-in on 10 August.
The first disclosure covered 11,742 customers whose full details leaked and 1,947 whose exposure was limited to name, city and email. Those orders were placed between 10 May and 8 August this year across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Hackers got in through a flaw in Metabase, a business analytics tool ShipMonk uses. The bug, tracked as CVE-2026-72898, scored 10.0 out of 10 for severity and was first reported around 6 August.
ShipMonk has secured the affected systems since. It has not said anything publicly about the incident.
Trezor has not decided yet whether to keep working with the company.
Why home addresses matter more than emails
Trezor said this is the first time in its history, going back to 2013, that customer phone numbers and home addresses have leaked.
A stolen email address means better-looking scam emails. A stolen home address, phone number and proof that someone owns a crypto wallet means something more serious.
Ledger holders learned this the hard way. A 2020 breach at the rival wallet maker exposed more than 270,000 customers, and the data ended up posted on a hacking forum. Years later, people were still getting scam calls and fake letters in the post, some containing counterfeit devices.
The leaked list here is essentially a directory of people who bought crypto storage hardware, with their addresses attached.
Trezor has warned customers about phishing and, given the addresses involved, possible physical security risks too.
The fix is not collecting the data at all
Trezor is building an anonymous delivery option using locker pickup, which automatically deletes shipping details once a package arrives.
Europe gets it this month. The US should follow by the end of the year.
It tackles the actual problem. Data that never reaches a courier cannot sit forgotten in their database for five years and turn up in a breach. Deletion policies only work if the other company actually deletes.
There is a wider lesson here for the industry. Buying a hardware wallet involves two kinds of security: the device protects your coins, and the purchase is supposed to protect your identity. The second part has now failed at both of the biggest manufacturers.
What to do if you are affected
Trezor has emailed everyone on the list. If you did not get a message, you are not affected.
Be suspicious of any contact claiming to be from Trezor, whether by email, phone or post. Trezor will never ask for your recovery seed, ever, through any channel.
If a device turns up in the post that you did not order, do not use it. Check firmware only through official channels.
The leaked data cannot be taken back. Scam attempts may not arrive for months or even years.
FAQ
How many people are affected?
Around 80,700 in total. The August disclosure covered 13,689 customers, and Friday’s update added roughly 67,000 more.
Are Trezor wallets still safe?
Yes. Trezor’s systems were not breached, and private keys, firmware and seed backups were not touched. The leak came from a third-party shipping company.
What should I watch out for?
Scam emails, calls and letters, plus any unexpected device arriving by post. Trezor will never ask for your recovery seed.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.


















