
Trezor has expanded the scope of its ShipMonk data breach after discovering that personal information belonging to approximately 67,000 additional U.S. customers was exposed from orders dating back as far as 2019.
The newly identified customers ordered Trezor devices between November 2019 and August 2021. Exposed records include names, email addresses, phone numbers, shipping addresses and order numbers, substantially widening an incident initially believed to be limited largely to recent purchases.
The discovery conflicts directly with Trezor’s customer-data retention policy. ShipMonk had repeatedly provided written assurances that older shipping information had been deleted in line with contractual requirements, Trezor’s data policy and previous communications between the companies.
The hardware-wallet maker initially disclosed the ShipMonk breach on August 13 after learning that unauthorized actors had accessed customer information held by the logistics provider. That first investigation identified 11,742 customers whose names, emails, phone numbers and shipping addresses were exposed, plus another 1,947 with partial exposure.
At the time, a 90-day deletion requirement was expected to limit the breach to recent orders. The newly discovered 2019-2021 records demonstrate that substantially older customer information remained inside ShipMonk’s systems despite those requirements.
Trezor systems, firmware, private keys and wallet backups were not compromised. The exposure occurred inside ShipMonk’s fulfillment infrastructure rather than the hardware wallets themselves.
Names, phone numbers and physical delivery addresses can give attackers enough information to construct highly personalized phishing attempts aimed specifically at known hardware-wallet owners.
Victims may receive fraudulent emails, phone calls or physical letters impersonating Trezor, exchanges, banks or delivery companies. Trezor is instructing customers never to disclose or enter a wallet backup in response to any communication claiming that a device, account or recovery phrase needs urgent verification.
The company has dealt with third-party exposure risks before. A separate Trezor.io incident in December 2025 involved suspicious activity linked to an external service, although no databases, devices or wallet software were compromised in that case.
Trezor is developing an Anonymous Delivery option designed to reduce the amount of personally identifiable information attached to hardware-wallet purchases. Planned features include locker collection, neutral packaging, generic sender information and automatic deletion of shipping identifiers after delivery.
The service was targeted for European availability around September 2026 and a U.S. rollout before the end of the year. The newly discovered historical records increase the known exposure from the ShipMonk breach well beyond the original 13,689 customers, with approximately 67,000 additional U.S. buyers from November 2019 through August 2021 now being notified.
The post Trezor ShipMonk Breach Expands to 67,000 More U.S. Customers appeared first on Crypto Adventure.