Trezor's ShipMonk Breach Now Affects More Than 80,000 Customers After Five-Fold Expansion
Hardware wallet maker confirms logistics partner retained customer records for years beyond its own stated deletion policy, raising physical security concerns for users in high-adoption markets worldwide.
Trezor confirmed on September 4, 2026, that a data breach at US fulfillment partner ShipMonk has affected more than 80,000 customers in total, after a second tranche of 67,000 additional US records surfaced dating back to a prior logistics partnership window spanning November 2019 through August 2021. The company says it received the updated scope from ShipMonk on September 2, two days before making it public. No hardware wallets, private keys, firmware, wallet backups, or Trezor infrastructure were accessed at any point.
The expanded figure is approximately five times larger than the initial count disclosed on August 13, which covered 13,689 customers whose orders were placed between May and August 2026. Of those, 11,742 experienced full data exposure, meaning names, email addresses, phone numbers, shipping addresses, and order numbers were all compromised, while the remaining 1,947 experienced partial exposure limited to name, city, and email only. Exposed fields across both disclosure rounds include full names, email addresses, phone numbers, shipping addresses, and order numbers. Countries identified in the original disclosure include the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
This breach is the first in Trezor's 13-year history to expose phone numbers and physical shipping addresses, marking a categorically more serious data type than in prior incidents. A 2022 breach at email provider Mailchimp exposed Trezor customer email addresses, and in January 2024 a compromise of a third-party support portal affected approximately 66,000 users. ShipMonk first notified Trezor of the current incident on August 10, 2026.
A Retention Failure, Not Just a Breach
The more structurally significant problem revealed by the September 4 update is not the size of the exposure but why records from 2019 to 2021 still existed at all. Trezor's own privacy policy requires fulfillment partners to delete or anonymize order data within 90 days of delivery. ShipMonk's retention of records that are now up to seven years old represents a direct violation of Trezor's stated data governance policy. The breach's root cause, according to reporting by BleepingComputer, was a vulnerability in Metabase, a third-party analytics tool embedded in ShipMonk's operations. The extortion group ShinyHunters, which operates a pay-or-leak model and has been linked in 2026 to breaches involving hundreds of millions of records at targets including Canvas/Instructure (275 million records), Ernst and Young, and McKesson (284 million patient records claimed), sent extortion communications to ShipMonk in connection with the incident.
Trezor stated in its disclosure: "We were informed on September 2 that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional US customers." The company reiterated that its internal systems were not touched and that no wallet credentials were involved.
Physical Risk Is the Lasting Concern
Security researchers and journalists have flagged the specific nature of this data as a compounding risk beyond ordinary phishing. When a shipping address is paired with a verified hardware wallet purchase, the resulting record is more useful to bad actors than a generic email leak. TechCrunch security editor Zack Whittaker described this targeting vector as "wrench attacks," meaning physical coercion of known crypto holders using their real-world location data. CertiK's H1 2026 security report counted 52 physical attacks on crypto holders in the first half of the year, up 33 percent from 39 in the same period of 2025.
According to CoinLaw, Trezor holds roughly 30 percent of the global hardware wallet market and shipped 2.4 million devices in 2024. CoinLaw also estimates that approximately 30 million people out of an estimated 400 million global crypto users hold assets in self-custody wallets of any type, making Trezor's logistics data a high-value target. Industry reports placed global losses tied to self-custody-related scams at an estimated 17 billion dollars in 2025, underscoring the scale of criminal interest in any dataset that confirms hardware wallet ownership.
Regional Exposure: South Asia and Africa Face Indirect but Serious Risks
The 2019 to 2021 records are US-specific, but the downstream threat is not. India ranked first in the Chainalysis 2025 Global Crypto Adoption Index, with Pakistan also in the top five. Both markets have well-documented exposure to WhatsApp-based phishing and SIM-swapping schemes. A phone number linked to a confirmed hardware wallet purchase creates a ready-made target list for those campaigns, and threat actors have been documented repurposing leaked datasets across borders. The region's susceptibility to large-scale social-engineering fraud is illustrated by Treasure NFT, a scheme that cost users across South Asia an estimated 800 million dollars.
In Sub-Saharan Africa, crypto transaction volume grew 52 percent year over year according to Chainalysis, with Nigeria leading the continent in adoption. African users are not represented in the US-centric ShipMonk records, but the breach illustrates systemic risk across the global hardware wallet supply chain. Trezor and Ledger are both widely recommended in Nigerian user guides, and similar logistics arrangements may exist for international orders. Fraud schemes in the region, including the CBEX operation that cost Nigerian users an estimated 250 million dollars, have already shown how quickly local threat actors can weaponize any available personal data tied to crypto activity.
What Comes Next
Trezor advises affected customers not to respond to any unsolicited contact, even from callers who accurately reference order details. The company recommends never entering a 24-word seed phrase online or in response to any message, regardless of how official it appears. For future purchases, the company suggests using a P.O. box, a pseudonymous email address, and paying in cryptocurrency rather than by card.
On the infrastructure side, Trezor says an Anonymous Delivery option featuring locker pickup and automatic identifier deletion after delivery is rolling out in the EU this month, with a US launch planned before the end of 2026. The company has not announced plans to extend the feature to markets beyond the EU and US, leaving users in South Asia, Africa, and other high-adoption regions without a comparable privacy-preserving purchase option for the foreseeable future.