Trezor disclosed that an additional 67,000 customers in the United States were affected by a data breach involving its shipping provider ShipMonk, significantly expanding the number of users exposed in the incident. The latest disclosure adds to concerns over the protection of customer information held by third-party service providers used by cryptocurrency companies.
The hardware wallet maker said on September 4 that the newly identified records belonged to U.S. customers who placed orders between November 2019 and August 2021. The exposed information included customer names, email addresses, phone numbers, shipping addresses and order numbers.
The latest disclosure raises the total number of Trezor customers affected by the ShipMonk breach to 80,689, with more than 67,000 of those users based in the United States.
The incident initially came to light on August 13, when Trezor said ShipMonk had notified the company of unauthorized access to systems containing customer information. At the time, the breach was reported to involve customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal whose orders had been fulfilled within the 90 days preceding August 8.
Earlier Disclosure Covered Nearly 14,000 Customers
Trezor’s initial disclosure identified 11,742 customers whose names, email addresses, phone numbers and shipping addresses had been exposed. Another 1,947 customers were identified as having partial information exposed, including their names, cities, and email addresses.
The newly disclosed records substantially increase the scale of the incident. Unlike the customers identified during the initial investigation, the additional U.S. users placed their orders over a much longer period, covering transactions made between November 2019 and August 2021.
Trezor said it had contacted all customers identified as being affected by the breach. The company indicated that customers who did not receive a notification email should not be considered part of the newly identified group.
The company also emphasized that the breach did not compromise its hardware wallets or internal systems. According to Trezor, customer devices remain secure despite the exposure of personal information through its external shipping provider.
Users Warned About Follow-Up Attacks
Although the company said the hardware devices and its own systems were not compromised, the exposure of names, contact information, and shipping addresses could create additional security risks for affected customers.
Trezor urged users to remain cautious about communications that appear to originate from the company or other trusted services. Potential threats include fraudulent emails, phone calls, and physical letters designed to exploit information obtained through the breach. The availability of shipping addresses also creates concerns beyond digital fraud, particularly for users who may own cryptocurrency hardware containing access to valuable digital assets.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S
— Trezor (@Trezor) September 4, 2026
Trezor has warned affected customers to remain alert for phishing attempts, impersonation scams and potential physical-security threats following the exposure of their personal information.
Data Deletion Claims Under Scrutiny
The breach has also raised questions about how customer records were handled by ShipMonk after Trezor requested their removal. Trezor said it had repeatedly sought and received written assurances from the shipping provider that the relevant customer information would be deleted.
However, the company said the data remained within ShipMonk’s systems despite those assurances. The development has added another layer to the incident, shifting attention toward data retention practices and the safeguards applied by third-party service providers.
The episode highlights a broader challenge for hardware wallet companies, which may need to balance product security with the protection of customer information collected during purchases and deliveries. While the wallet devices themselves were not reported to have been compromised, exposed personal records can provide attackers with information that may be used in targeted social-engineering campaigns.
As the investigation continues, affected customers are likely to face increased attempts at impersonation and fraud. The expanding breach underscores the security risks associated with customer data held outside a cryptocurrency company’s own infrastructure, even when the underlying hardware wallet systems remain uncompromised.






