Trezor says 67,000 more U.S. customers were exposed in a breach at its shipping provider, pushing the known affected total above 80,000.
Key Points:
- 67,000 additional U.S. customers had full order information exposed, lifting the known total above 80,000.
- The newly identified records date from November 2019 through August 2021.
- Trezor says its systems, devices, private keys and wallet backups were not compromised.
Trezor Breach Expands
In a Sept. 4 update, Trezor said another 67,000 U.S. customers were affected, with records tied to orders placed between November 2019 and August 2021.
The exposure included names, email addresses, phone numbers, shipping addresses and order numbers. All newly affected customers have been notified by email.
ShipMonk, Trezor's logistics provider, had kept those records even though Trezor said it repeatedly requested deletion and received written assurances that the data had been removed under its contract and data policy. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.
That takes the known total above 80,000. Trezor's August notice said 11,742 customers had names, emails, phone numbers and shipping addresses exposed, while 1,947 had more limited information compromised.
Also Read: Bitcoin Posts Best Month Since 2024, Yet Fidelity Won’t Call The Bottom
Crypto Security Risk
Trezor said its own systems were not breached, and the incident did not expose private keys, wallet backups or device secrets. The company said its hardware wallets remain secure.
The main risk is the leaked customer data, which can help attackers identify hardware wallet owners and tailor scams around information that appears legitimate.
Trezor warned affected users to expect fake emails, fraudulent calls and physical letters, and it also highlighted possible physical-security threats. That makes the exposure more than a conventional account-security problem.
Security firm TRM Labs has argued that self-custody does not eliminate risk, but shifts it to different parts of the security chain. In this case, the wallet itself may remain protected while shipping records expose the owner’s identity, contact details and home address.
The incident was first disclosed Aug. 13, when Trezor said ShipMonk's breach affected about 13,689 customers and initially tied most exposure to recent orders under a 90-day retention policy.
The later discovery of records dating back to 2019 shows older customer data remained in ShipMonk's systems despite Trezor's deletion requirements.
Read Next: iPhone Ultra May Land At $2,550 Average, Helping Apple Redraw Foldable Market





