Trezor’s ShipMonk Breach Widens Sharply: 67,000 More US Customers Now Confirmed Affected

Hardware wallet maker Trezor has significantly widened the scope of a data breach that traces back to its third-party shipping provider, ShipMonk, revealing that roughly 67,000 additional US customers had their personal information exposed on top of the smaller group already disclosed last month. Combined with the original disclosure, the number of Trezor customers whose data was compromised in this incident now stands at over 80,000.
August 10: ShipMonk reports unauthorized access
The chain of events began when ShipMonk, the logistics company Trezor uses to fulfill orders, detected unauthorized access to its systems. ShipMonk traced the intrusion to a vulnerability in Metabase, an analytics platform it uses internally, which an attacker exploited to reach account and customer data. ShipMonk informed Trezor of the incident on August 10.
August 13: The first disclosure
Trezor went public with the breach on August 13, telling customers that orders placed within the prior 90 days across the US, UK, and five other countries may have been affected. That initial round covered a comparatively narrow group — some 11,742 customers with full data exposure (names, emails, phone numbers, shipping addresses) and roughly 1,947 more with partial exposure. Trezor stressed at the time, and has repeated since, that its own infrastructure was never touched: no devices were compromised, no wallet seeds or private keys were exposed, and no funds were at risk.
September 2: ShipMonk reports a much larger footprint
Nearly three weeks later, ShipMonk came back to Trezor with an update: the breach was considerably larger than first understood. Records dating back further than the original 90-day window — specifically orders placed between November 2019 and August 2021 — had also been accessed.
September 4: Trezor discloses the expansion
Trezor confirmed publicly that an additional roughly 67,000 US customers from that 2019-2021 window were affected, with exposed data including full names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said it has directly emailed every customer confirmed to be affected, and that anyone who did not receive such an email is not part of either disclosed group.
What stays consistent throughout
Across both disclosures, the underlying facts haven’t changed: this is a breach of a third-party shipping vendor’s systems, not of Trezor’s own servers, apps, or devices. No cryptocurrency has been stolen as a direct result, and no wallet recovery phrases were ever at risk, since Trezor’s shipping partner never had access to that kind of information in the first place. The real risk to affected customers is downstream — targeted phishing attempts, fake support calls, or fraudulent shipping notices that use the leaked personal details to appear more convincing, given that anyone on this list is now confirmed to own a hardware wallet.
This article is for informational purposes only and does not constitute security or financial advice. If you believe your data may have been exposed in this or any similar breach, remain alert for phishing attempts and never share your wallet recovery phrase with anyone.
Learn the fundamentals of keeping self-custodied assets safe over at the Bitcoin Academy.
