Trezor: Shipping Breach Exposed 80,689 Customers’ Details

Trezor attributes the incident to a breach at ShipMonk, its fulfillment and shipping partner, not to any compromise of its own infrastructure. The company’s cur...

Trezor: Shipping Breach Exposed 80,689 Customers’ Details

Trezor says a breach at one of its shipping providers exposed the contact and delivery details of 80,689 customers, the hardware wallet maker disclosed in its official incident notice, stressing that its own systems, products and devices were not compromised.

TLDR Keypoints

  • Trezor says a third-party shipping provider suffered a data breach.
  • Customer contact and delivery details were exposed.
  • 80,689 customers were affected, according to Trezor.

Trezor reports shipping-provider breach affecting 80,689 customers

Trezor attributes the incident to a breach at ShipMonk, its fulfillment and shipping partner, not to any compromise of its own infrastructure. The company’s current incident FAQ states that 80,689 customers are affected. For related coverage, see Trezor Announces Launch of Quantum-Ready Safe 7 Hardware Wallet.

Customers affected, according to Trezor

80,689

Trezor’s current incident FAQ states that 80,689 customers were affected by the ShipMonk breach. Exposure varies by cohort; this is the updated overall total, not the original full-exposure count. Source: Trezor official incident notice, as cited in the September 12, 2026 research brief.

The current total is far larger than the original disclosure, published August 13, which counted 11,742 customers with full exposure and 1,947 with partial exposure. Those figures represent the original cohort, not the updated overall count.

In a September 4 update, Trezor said it was informed on September 2 that the breach included roughly 67,000 additional US customers, tied to orders placed between November 2019 and August 2021. Trezor said those historical records remained despite repeated requests and written assurances from ShipMonk confirming deletion.

We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
— Trezor Team, official incident update

Trezor describes a 90-day customer-order-data retention policy, which is why the surviving 2019 to 2021 records ran counter to what the company says it expected from its vendor. This is the second data-handling incident to touch Trezor customers, following its earlier disclosure of a breach at an email provider.

What customer information was exposed?

Contact and delivery details

Trezor says the exposed full-delivery dataset includes names, email addresses, phone numbers, shipping addresses, and order numbers. The company separately identifies the 1,947 partial-exposure records as name, city, and email, without a shipping address.

Crucially, Trezor says its systems, products and services were not compromised and its devices remain secure. This is a contact and order-data incident, not an established theft of wallet keys.

What the report does not establish

The disclosure does not indicate that passwords, payment information, private keys or recovery phrases were involved. Trezor says it notified affected customers directly and advises them never to share a wallet backup or enter it on a website.

Trezor warns that exposed contact details can enable phishing emails, fraudulent calls or letters, and potential physical-security risks. These are warned-about risks rather than verified consequences of this dataset. Rival Ledger has documented similar campaigns, including physical letters directing recipients to scan a QR code and enter recovery words, though those are separate Ledger incidents, not attacks tied to this Trezor data. The pattern echoes long-running concerns that Trezor hardware users have been targeted by phishing.

Similar exposure has hit competing brands this year, including a SafePal breach affecting more than 53,000 crypto owners, underscoring that vendor-side data handling is an industry-wide risk. Trezor has meanwhile continued product work, recently launching its quantum-ready Safe 7 wallet.

What remains unclear about the breach

Trezor attributes the surviving records and deletion assurances to ShipMonk, but no independent audit of the vendor’s conduct or the affected-customer dataset has been verified. Treat the counts and the deletion narrative as Trezor’s attributed statements.

No confirmed downstream theft, fraud or physical attack tied to these records has been established, and a widely circulated analysis claiming zero financial damage is, according to unconfirmed reports, not corroborated by the official notice. Reports attributing the original intrusion to a Metabase vulnerability also remain unverified.

Bitcoin traded at $77,159, down 0.32% over 24 hours, at the time of the research snapshot; there is no evidence linking the disclosure to price action. What to watch next: further Trezor FAQ updates, any ShipMonk statement, and whether affected customers report targeted phishing in the days ahead.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

More From Crypto News

Akita Inu

Author

Akita Inu

Akita Inu covers fast-moving crypto market updates, exchange news, and token ecosystem developments for CoinLive, with a focus on concise source-led reporting.