Hardware wallet manufacturer Trezor disclosed that a breach at logistics provider ShipMonk exposed contact and order information for approximately 67,000 additional U.S. customers. The incident, first reported on August 13, originally affected 13,689 people; the new disclosure brings the total exposure to roughly 80,689 users, though Trezor has not confirmed whether the two groups overlap.
The newly disclosed records cover U.S. orders placed between November 2019 and August 2021. The exposed data includes names, email addresses, phone numbers, shipping addresses and order numbers, which can link an identifiable person and physical location to a hardware‑wallet purchase—a risk that extends beyond a typical email leak.
Root Cause and Timeline
When Trezor first disclosed the breach on August 13, it reported 11,742 customers with full exposure and 1,947 with partial exposure. Trezor’s initial statement indicated that older order data had already been deleted. An August 14 clarification acknowledged that some partially exposed records included older orders.
The September 4 update reversed that understanding. Trezor said it had repeatedly requested written assurances from ShipMonk that the data had been destroyed, yet records dating from 2019‑2021 remained on the vendor’s systems. ShipMonk’s retained logs were found despite a published delivery‑data policy that mandates deletion of customer details after 90 days, with exceptions for unresolved order issues.
Breach analysis points to a vulnerability in the analytics platform Metabase. A zero‑day flaw allowed an unauthorized session to be created tied to an administrator account, enabling bulk table downloads. This access was attributed to the original compromise of ShipMonk’s environment.
Impact and Response
The breach did not affect Trezor’s wallet systems, products or services. Recovery seeds, private keys and wallet funds remain secure. However, the exposed fields could be used for convincing scam emails, fraudulent calls or letters, and potentially for physical targeting of hardware‑wallet owners.
Trezor has contacted every newly affected customer directly and urged users to avoid sharing wallet backups or entering seed phrases on any website. The company has not documented any downstream attacks resulting from the leaked dataset, but the risk remains.
For hardware‑wallet owners, the episode illustrates that protecting cryptographic keys alone does not erase the purchase trail created by fulfillment partners. Deletion policies provide limited protection unless a vendor’s compliance is independently verified.

