Trezor’s ShipMonk Breach Expands by 67,000 Customers
Older U.S. order records that should have been deleted widen a logistics-provider breach and increase phishing and physical-security risks.
Trezor has expanded the reported scope of a breach at logistics provider ShipMonk by about 67,000 U.S. customers, turning what began as a recent-order incident into a much larger test of data-retention controls. The newly identified records cover orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers.
The hardware-wallet company said ShipMonk informed it on September 2 that the breach was larger than previously stated. Trezor published the update on Friday, saying it had repeatedly received written assurances that the older data had been deleted in line with its contract and retention policy. All newly affected customers have been contacted directly, according to the company.
The development materially changes the scale of the August disclosure. Trezor initially said 11,742 customers had full contact details exposed and another 1,947 had partial exposure. Adding roughly 67,000 people takes the known affected population above 80,000. More importantly, it shows that data from a relationship ending years earlier remained available inside a third party's systems despite deletion commitments.
Trezor emphasized that its own systems, devices and services were not compromised. The exposed information does not include wallet backups or private keys, and possession of a customer's address is not enough to move crypto assets. That distinction matters technically, but it does not remove the security risk.
Names, phone numbers, email addresses, purchase history and physical addresses can be combined to create convincing impersonation attempts. An attacker can pose as the wallet manufacturer, a courier, an exchange or a bank and refer to a real purchase to establish trust. The objective is typically to persuade the customer to reveal a wallet backup, enter it on a fake website or approve a malicious transaction. Trezor says customers should never share a wallet backup or type it into a website.
Physical addresses create an additional concern for cryptocurrency owners. A hardware-wallet purchase can imply that a household controls digital assets, even though the package contents, wallet balance and on-chain addresses were not disclosed. The data can therefore increase the risk of targeted threats or harassment as well as online phishing.
The retention failure is the central governance issue. Trezor says its policy requires fulfillment partners to delete or anonymize personal order data 90 days after delivery, the minimum period it considers necessary for returns, refunds and replacements. The newly exposed records were years older. Contractual promises provide accountability after a failure, but they are not equivalent to technically verified deletion.
For merchants that outsource logistics, the incident highlights the difference between collecting less data and ensuring that every processor actually removes it. Effective controls may require deletion logs, independent audits, narrow access permissions and contractual rights to test compliance. Companies also need an inventory of historical processors because customer risk can persist long after a commercial relationship ends.
Trezor plans privacy-oriented delivery options using locker pickup, neutral packaging and automatic deletion of shipping identifiers. It has targeted availability in the European Union in September 2026 and in the United States by year-end. Those changes may reduce future exposure, but they do not resolve the consequences for people whose data has already escaped.
Why it matters
Self-custody protects crypto assets from the failure of an exchange or custodian, but it moves responsibility toward the owner and the surrounding supply chain. A secure device cannot protect a customer from a convincing phone call or letter built from breached order data. The episode demonstrates that operational metadata can become a security vulnerability even when cryptography performs exactly as designed.
The update is also a warning for fintech companies that promise short retention periods. Customers and regulators will increasingly ask whether deletion is independently verified across processors, backups and legacy systems. The gap between policy and execution is now the most consequential fact in this breach.
The investigation remains open. Trezor has not identified the attacker, disclosed whether the data has been misused or provided a final technical account of ShipMonk's compromise. Affected customers should treat unsolicited contact as untrusted and rely only on verified official channels.