Trezor, the company known for making hardware crypto wallets, has increased its estimate of how many customers were affected by a data breach at its shipping partner ShipMonk. In an update posted on 4 September, following up on an earlier notice from August, Trezor said it learned on 2 September that the breach also included order data from an older ShipMonk contract that ran from November 2019 through August 2021.
According to Trezor, that older batch of records affects roughly 67,000 additional customers in the United States. The information exposed for these customers includes full name, email address, phone number, shipping address, and order number.
Trezor said that throughout its working relationship with ShipMonk, it had specifically asked the company to delete this kind of data, and had even received written confirmation stating that the data had been deleted, in line with the terms of their contract and data policy agreements. The company wrote that it is very disappointed that, despite receiving this confirmation, the data was in fact not actually deleted from ShipMonk’s systems.
What was already known before this update
Trezor first told the public about this ShipMonk incident on 13 August. ShipMonk had informed Trezor on 10 August that an unauthorized party had gained access to systems containing customer order data.
At that time, the affected group included 11,742 customers whose full information was exposed, meaning their name, email, phone number, and shipping address, along with another 1,947 customers whose exposure was more limited, involving just their name, city, and email.
Those earlier affected orders were sent to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, mostly falling within a window between 10 May and 8 August 2026, tied to a data retention rule that was supposed to keep records for only 90 days. With this new batch of roughly 67,000 US records now added in, the total number of known affected customers has climbed above 80,000.
What was not actually stolen
Trezor has been clear that this breach happened at its shipping partner, not within Trezor’s own systems. The company says its internal systems, the hardware devices themselves, private keys, seed phrases, and wallet backups were never accessed in any way. Buying a Trezor device still meant handing over enough personal information to a fulfillment company just to get a package delivered to your door, and it is specifically that vendor side file which ended up leaking.
How to know if you are part of this newly affected group
Trezor says that every customer newly identified as affected has already been sent an email about it. If you did not receive a message from Trezor’s official notice email address, the company says you are not part of this particular group. It is worth being cautious here, any unexpected message claiming to be Trezor support, whether by email, text, or phone call, that asks you to connect your wallet, enter your seed phrase, or click a link to verify your shipment, should be treated as a scam. Official Trezor notices will never ask you for your recovery words under any circumstance.
The real risks that come from this kind of address leak
For someone trying to exploit this data, the valuable pieces here are a person’s identity, their home address, and the simple fact that this household is known to have purchased a hardware crypto wallet. Trezor specifically flagged a few risks worth watching for, including phishing emails or scam phone calls that reference a real order number to sound convincing, fake letters or packages sent to a person’s home, and physical safety risks tied to someone’s known shipping address.
That last point is exactly why hardware wallet companies have spent years debating whether to ship products in plain, unmarked boxes. Trezor said it is now speeding up its rollout of anonymous shipping options, so that future orders reveal less identifying information right at the customer’s doorstep.
What this incident does not mean
This does not mean Trezor’s device firmware was compromised or backdoored in any way. It also does not mean every single customer worldwide from that 2019 to 2021 period is affected, Trezor specifically limited this new group to US orders placed during that particular contract period. And it does not mean that someone who never had an order handled by ShipMonk is at risk here.
The core failure in this whole situation comes down to vendor data retention. Trezor’s 90 day retention rule was specifically designed to limit how much data could ever be exposed in an incident like this. But these older 2019 to 2021 records show that a partner company can still hold onto a file long after formally confirming, in writing, that it had already been deleted.
Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

