
Trezor data breach 2026 exposed nearly 81,000 customers through ShipMonk. See what leaked, what stayed safe and what users should do.
Author: Kritika Gupta
4th September 2026- Hardware wallet maker Trezor confirmed on Friday, that the data breach at its shipping partner ShipMonk is far larger than first reported. The company said another 67,000 US customers had their full order details leaked. The Trezor data breach now covers roughly 80,700 identified people across two disclosures.
High Signal Summary For A Quick Glance
Sam
@hraqhraq
@Trezor @TimKotzman Trezor should sue them for this, if they don’t, then they might not be serious about protecting customers as they claim, and should do disclaimer that your data with us might be compromised due to shipping companies we select 🙀
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 https://t.co/yDQvTlAA2S
01:05 PM·Sep 4, 2026
Pink Power
@hodllng
@Trezor Why was shipmonk lying to you guys? What will you do to ensure your future shipping providers aren’t lying to you about deleting customer personal information? They can continue lying, what can Trezor actually do about it? How will you ensure your shipping provers will delete
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 https://t.co/yDQvTlAA2S
12:49 PM·Sep 4, 2026
bitcoin idiot⚡️
@btcidiot
@Trezor @punk6529 You can have the best hardware wallet in the world, it still won’t protect you against a $5 wrench attack. Another 67k people got a target on their back. Anonymous delivery should have been the default option since day 1.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 https://t.co/yDQvTlAA2S
11:59 AM·Sep 4, 2026
High attention and emotional sentiment detected.
Trezor led with one reassurance. Its own systems, devices, private keys, and wallet backups stayed safe. The leak involves customer shipping data, not the crypto itself.
Trezor posted the news on X and updated its living security advisory. The company said ShipMonk warned it two days earlier, on September 2, that the breach reached further than anyone thought.
The newly exposed group ordered a Trezor device between November 2019 and August 2021. All of them are US customers. So the fresh cohort sits years apart from the first batch.
Trezor first went public on August 13. That disclosure named 11,742 full exposures and 1,947 partial ones, or 13,689 people. Those orders spanned May to August 2026 across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
For the new 67,000 US buyers, the leak is complete. It includes each customer’s name, email, phone number, shipping address, and order number.
Trezor drew a hard line around what stayed protected. The Trezor data breach did not touch its own systems, its hardware, private keys, or recovery seeds. Parcel contents also stayed sealed.
Amazon shoppers can relax too. A different partner fulfills Trezor’s Amazon storefront, so those orders sit outside this incident, according to Trezor.
Trezor–ShipMonk breach disclosures at a glance
The entry point sat with a third tool, not with Trezor or even ShipMonk directly. ShipMonk told customers that attackers exploited a flaw in Metabase, a business analytics platform.
Metabase flagged the unauthorized access to ShipMonk around August 6. Later reporting tied the intrusion to a SQL-injection zero-day that handed attackers admin access. SecurityWeek also noted that the extortion crew ShinyHunters claimed a related Metabase attack, though that link remains unconfirmed.
Analytics tools like Metabase often hold broad read access to production databases. So a single injection bug can dump customer tables without ever touching a wallet’s secure chip.
Key milestones related to this development
ShipMonk retains records containing customer names, emails, phone numbers, shipping addresses and order numbers.
Metabase alerts ShipMonk that an unauthorized party exploited a software vulnerability to access customer data.
ShipMonk informs Trezor that attackers accessed systems containing customer shipping information.
Trezor reports 11,742 fully exposed records and 1,947 partially exposed records, totaling 13,689 customers.
ShipMonk tells Trezor that the incident also includes historical US orders from November 2019 through August 2021.
Trezor identifies approximately 67,000 additional affected US customers, raising the estimated total to roughly 80,700.
Watch for confirmed phishing campaigns, physical-security incidents, regulatory filings or evidence that the dataset has been sold or published.
Trezor’s sharpest frustration centers on data that should not have existed. Throughout the relationship, Trezor says it repeatedly asked for and received written confirmation that ShipMonk deleted old order data.
We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
That older cooperation, back in 2019 to 2021, predated Trezor’s current 90-day retention policy. Still, Trezor says it requested deletion when the arrangement ended, and ShipMonk confirmed the job in writing.
So the 2026 leak of 2019 records undercuts the earlier reassurance. Decrypt wrote that Trezor’s retention argument now looks considerably weaker. Cybersecurity News reached a similar view.
A leaked address list matters more for hardware wallet buyers than for most shoppers. These customers self-custody crypto, and now their names sit next to a doorstep.
Scammers can craft convincing phishing that cites a real order number and street. They can also pose as Trezor, a bank, or a courier by mail, call, or text.
The threat even reaches the physical world. Trezor warned customers to watch for fake emails, fraudulent letters, and potential risks to physical security. Analysts often call this the wrench attack, where a thief simply targets a known holder in person.
The seeds themselves never sat in ShipMonk’s systems. So the danger here is social engineering and coercion, not a remote drain of the device.
This marks the third time a vendor has leaked Trezor customer data. A 2022 Mailchimp phishing attack exposed roughly 106,856 customers. A 2024 support-portal breach exposed up to 66,000 names and emails, and attackers emailed 41 users asking for recovery seeds.
Observers keep drawing one comparison. Ledger suffered a 2020 e-commerce database leak that spilled names, emails, addresses, and phones. That dump fueled years of phishing and physical threats, and CoinDesk places this Trezor data breach in the same lineage.
Trezor is pushing a fix it calls Anonymous Delivery. The option promises locker pickup, neutral packaging, a generic sender, and auto-deletion of shipping IDs.
The company aims to launch it in the EU by September 2026 and in the US late in 2026. Meanwhile, affected customers should receive an email from help@trezor.io, though Trezor says those messages can take time to arrive.
For now, treat every unexpected Trezor message with suspicion, and never enter a recovery seed anywhere but the device. None of this is financial advice, yet the security math is simple. Guard the seed, verify the sender, and assume scammers already know your address.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Trezor Data Breach Widens to 67,000 More US Customers
Core DAO Finds Bug Behind Excess Validator Rewards
Avici Users Get Full Refunds After Card Exploit
Kraken Dust Attack Locks Users as HTX Funds Spread
Trezor Data Breach Widens to 67,000 More US Customers
Core DAO Finds Bug Behind Excess Validator Rewards
Avici Users Get Full Refunds After Card Exploit
Kraken Dust Attack Locks Users as HTX Funds Spread