Security Hub

Trezor Breach Exposes 80K+ Customers After ShipMonk Deletion Failed

Published: Sep 5, 2026By Aleksandar Dukic

Key Analysis

Trezor says a ShipMonk breach exposed roughly 80,689 customers after shipping records that were supposedly deleted were found intact. What crypto holders should do.

Trezor Breach Exposes 80K+ Customers After ShipMonk Deletion Failed

Listen To This Article

Trezor Breach Exposes 80K+ Customers After ShipMonk Deletion Failed

4m 48s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Trezor has widened the scope of a data breach tied to its fulfillment partner ShipMonk, telling customers that shipping records supposedly deleted years ago were still sitting in the vendor's systems when attackers reached them. The larger disclosure implies roughly 80,689 affected customers, a sixfold jump from the company's earlier count, with about 67,000 additional US buyers pulled in.

The details come from a CryptoSlate report published on September 5, 2026. Trezor has not put out a single combined total or a row-level breakdown of exactly what leaked for each customer, so the 80,689 figure is an implied sum rather than a number the company has confirmed as final.

Deleted records that were never deleted

The most damaging part of this is not the breach itself. It is the reason the count grew. Trezor says ShipMonk held old shipping records that should have been purged, and that the vendor had provided written assurances the data was gone. Those records were found intact and exposed.

That gap between a written deletion promise and the reality on the vendor's servers is the story here. A company can run a clean internal security program and still have customer data leak because a third party it hired years ago never actually erased what it said it erased. Data retention is not a checkbox at signup. It is an ongoing obligation that has to be verified, not assumed.

For a hardware wallet maker, the stakes are specific. Trezor sells self-custody. The entire pitch is that you hold your own keys and no company can move your funds. That protection still holds here: a shipping database does not contain private keys, seed phrases, or PINs, and no on-chain funds are at risk from this leak. The exposed data is the physical layer around the wallet, not the cryptography inside it.

The real risk is a targeted phishing list

Names, shipping addresses, email addresses, and order histories are exactly what a phishing operation wants. This is not a generic email dump. It is a list of confirmed hardware wallet buyers, tied to real home addresses, sorted by the fact that every person on it owns crypto and takes custody seriously enough to buy a cold storage device.

Attackers can use that to send convincing fake "security alert" emails, fake firmware update prompts, or even physical mail with a doctored device or a QR code that routes to a malicious setup page. The 2025 wave of counterfeit Ledger letters mailed to breach victims is the template every crypto holder should keep in mind: a real address plus a real product name makes a scam far harder to dismiss.

Practical steps for anyone who bought a Trezor:

  • Treat any unsolicited Trezor email, letter, or call as hostile until proven otherwise. The company will never ask for your seed phrase or PIN, and no legitimate support process ever requires it.
  • Never enter your recovery seed into a website, app, or form. It goes into the device only.
  • Verify firmware and setup steps through Trezor's official app and documentation, not through links sent to you.
  • Be extra skeptical of physical mail referencing your device. A correct address does not make the sender legitimate.

Custody protects keys, not your identity

This breach is a reminder that self-custody solves one problem cleanly and leaves another wide open. Holding your own keys removes counterparty risk over your funds. It does nothing about the personal data trail created when you buy the hardware, top up a card, or complete KYC with any provider in the chain.

The same logic applies across the self-custody card market. A non-custodial card that spends from your own wallet keeps an exchange from freezing your balance, but the issuer, the fulfillment partner, and the KYC processor still collect names and addresses that can leak later. Custody design and data privacy are two separate risks, and buyers routinely conflate them. Providers like Ledger and other hardware-linked spending products carry the same exposure: the device is secure, the paperwork around it is a liability.

Vendor-side data handling deserves as much scrutiny as the security of the device itself. A wallet can be flawless and still put you on a targeting list if the company shipping it keeps records it promised to delete.

Overview

Trezor's breach disclosure has grown to roughly 80,689 implied customers after shipping records that ShipMonk claimed to have deleted were found intact, adding about 67,000 US buyers to the count. No private keys or funds are exposed, but names, addresses, and order details are, which hands attackers a precise phishing list of confirmed crypto holders. The lesson is blunt: self-custody protects your keys, not your identity, and a vendor's written deletion promise is worthless without verification. Assume any Trezor-branded outreach is a scam until you confirm it through official channels, and never enter your seed anywhere but the device.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.