Trezor Said the Old Customer Data Was Deleted. Another 67,000 Records Just Proved Otherwise
- The Mess: Trezor has revealed that another 67,000 U.S. customers were caught in the ShipMonk data breach after years-old order records that were supposed to have been deleted were found in the compromised systems.
- The Damage: Attackers now potentially have names, phone numbers, email addresses, home addresses and order details belonging to confirmed hardware wallet customers.
- The Fix: Treat every unexpected Trezor-related email, phone call or physical letter as a potential phishing attempt and never enter a wallet backup into a website.
Trezor’s data breach just got much bigger.
When the hardware wallet manufacturer disclosed the ShipMonk incident in August, the company said the exposure was limited partly because customer data was supposed to be deleted or anonymized after 90 days.
Now another 67,000 customers have appeared in the breach.
And their orders are not recent.
The newly identified records belong to U.S. customers who ordered Trezor products between November 2019 and August 2021.
Some of the exposed data is almost seven years old.
According to Trezor, ShipMonk informed the company on September 2 that the breach was significantly larger than initially understood. The additional records include customers’ names, email addresses, phone numbers, shipping addresses and order numbers.
That takes the known impact of the ShipMonk incident from roughly 13,689 customers to more than 80,000.
The original disclosure covered 11,742 customers whose full contact and shipping information was exposed, plus 1,947 customers with partial exposure.
Then came the extra 67,000.
The uncomfortable question is obvious.
Why was data from 2019, 2020 and 2021 still there?
Trezor says it repeatedly requested deletion of the customer information throughout its relationship with ShipMonk and received written confirmation that the records had been deleted in line with the companies’ agreement and data policy.
They had not been.
At least not from the systems eventually compromised.
That changes the entire story.
This isn’t simply a breach where a logistics provider lost customer information it was actively using to ship recent orders.
Old data that was allegedly gone was still sitting inside the environment.
Trezor’s own systems were not compromised.
The company’s hardware wallets were not compromised.
Private keys were not compromised.
Wallet backups and seed phrases were not exposed.
That distinction is important.
Attackers did not get the keys needed to directly steal cryptocurrency from the affected wallets.
But that doesn’t mean the data is harmless.
Quite the opposite.
The leaked information can identify someone as a Trezor customer.
And for criminals, that can be valuable intelligence.
A random email address is one thing.
A name, phone number and home address connected to someone known to have purchased a cryptocurrency hardware wallet is something else.
It creates a much better target for phishing.
Attackers can send fake security alerts.
They can make convincing phone calls.
They can send fraudulent letters to a physical address.
They can impersonate Trezor support.
And they can use real order information to make the scam look legitimate.
Trezor has specifically warned affected customers about fake emails, phone calls and physical letters.
The company also warned about potential physical-security concerns.
That may sound dramatic, but hardware wallet customers are a very specific category of target.
The attacker doesn’t know how much cryptocurrency a customer owns.
But the order information provides one useful clue:
This person bought a device designed to protect cryptocurrency.
That can be enough to make them worth targeting.
The incident also exposes a problem that extends far beyond Trezor.
Companies increasingly rely on third parties to handle everything outside their own core systems.
Payment processors.
Cloud providers.
Analytics platforms.
Customer-support systems.
Shipping companies.
Fulfillment warehouses.
Every one of those partners can become another copy of the company’s customer database.
And deletion policies are only useful if somebody actually deletes the data.
A company can have a perfectly reasonable retention policy on paper.
It can say customer information disappears after 90 days.
It can receive written confirmation that the deletion happened.
And years later, the same records can still be sitting on a third-party system waiting for an attacker to find them.
That is the supply-chain problem hiding inside this breach.
Trezor didn’t need to lose control of its hardware wallets.
It only needed a shipping partner holding information that should no longer have existed.
And that was enough.
- The Damage: More than 80,000 customers are now known to be affected, exposing information that can be used to identify cryptocurrency hardware-wallet owners and build highly targeted phishing and social-engineering campaigns.
The real risk starts after the breach announcement disappears from the headlines.
Stolen contact information has a long shelf life.
Phone numbers often remain unchanged for years.
People don’t move every year.
Email addresses stay active.
And order information can be reused indefinitely to make a fake message look credible.
An attacker doesn’t need to compromise a wallet.
They can try to convince the owner to give them access instead.
That is why the most dangerous follow-up attacks may not arrive today.
They may arrive months from now.
Or years from now.
A fake Trezor email.
A fake security warning.
A phone call claiming that a device needs to be replaced.
A letter delivered to the victim’s actual home address.
The database doesn’t need to contain a seed phrase to become dangerous.
- The Fix: Affected Trezor customers should assume their contact and shipping information may be known to criminals, watch for highly targeted scams and never reveal a wallet backup or seed phrase to anyone.
Trezor says it has contacted the customers affected by the newly identified records.
Users should be particularly suspicious of messages claiming there is a problem with their wallet, account or device.
A legitimate security incident can also become perfect material for scammers.
“Your information was exposed in the ShipMonk breach.”
Sounds believable.
Because now it is.
That makes this exactly the kind of incident criminals can exploit for a second attack.
Users should independently verify any communication through official channels instead of clicking links or calling phone numbers provided in unexpected messages.
And the rule for wallet backups remains simple:
Never type your seed phrase or wallet backup into a website.
Not for support.
Not for a security check.
Not because an email says your device is at risk.
Not because someone already knows your name and address.
Bugstoday Opinion
The most interesting part of this breach is not the number.
It’s the timestamp.
2019.
2020.
2021.
Data that was supposedly deleted was still around years later.
That is the problem with modern data breaches.
Companies talk about retention policies as if deleting data were a philosophical position.
“We only keep it for 90 days.”
Great.
But where?
The main database?
The backup?
The analytics platform?
The logistics provider?
The contractor’s export?
The forgotten system nobody has looked at for three years?
Because data isn’t deleted when someone writes a policy.
It’s deleted when the last copy is actually gone.
And in this case, the last copy clearly wasn’t.
Trezor’s wallets were not hacked.
Private keys were not stolen.
Seed phrases were not exposed.
But tens of thousands of people can now potentially be identified as cryptocurrency hardware-wallet customers, complete with contact details and physical addresses.
Sometimes the safest part of the system is the hardware wallet.
And the weakest part is the company shipping the box to your house.
The wallet was secure. The shipping records were not.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
Trezor — Recent Customer Data Exposed in Shipping Provider Incident
Trezor — September 4, 2026 Customer Data Breach Update
The Block — Trezor Says ShipMonk Breach Affected Another 67,000 Customers
Decrypt — 67,000 More Trezor Customers Exposed as Data Breach Widens




