- The Trezor data breach now affects more than 67,000 users in the US, as the information stolen from its shipping provider dates back as far as 2019.
Trezor, the world’s first hardware wallet, originally disclosed a data leak affecting roughly 13,689 users across seven countries. The breach was traced to ShipMonk, its third‑party shipping provider, which accepted responsibility.
Further investigation has revealed that the incident is far larger than initially reported, with the number of compromised accounts now exceeding 67,000 in the United States alone.
The Trezor Data Breach Is More Serious Than We Thought
On Friday, Trezor announced that the leak now encompasses approximately 67,000 U.S. customers. According to ShipMonk’s updated records, the exposure dates from orders placed between November 2019 and August 2021.
Trezor had originally believed only shipments completed within a 90‑day window leading up to August 8 were at risk, citing its 90‑day data retention policy.
The heightened scope is attributed to ShipMonk’s failure to comply with its contractual data‑handling obligations and the assurances it gave Trezor that customer data would not be retained beyond the 90‑day limit.
Trezor expressed disappointment over the lapse but has not yet outlined any formal actions against ShipMonk.
Because of ShipMonk’s non‑compliance, the compromised records include full names, email addresses, phone numbers, shipping addresses and order numbers. The disclosed figure pertains only to U.S. customers; the impact on users in the UK, Sweden, Colombia, Brazil, Italy and Portugal remains unclear.
While Trezor’s own systems were not breached, the leaked data exposes users to targeted phishing campaigns and other cyber‑threats.
Reminders for Users
The company has already notified affected users of the expanded breach and urges them to remain alert to fraudulent emails, phone calls and letters. Trezor also warns of potential physical‑security risks, noting an increase in “wrenches attacks” targeting crypto holders.
Users are advised never to share their wallet backup phrase, even if the requester claims to be from Trezor, and to avoid entering the phrase into any website, legitimate or not.
“We’re terribly sorry to everyone affected,” Trezor posted on social media. “We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.”


