According to Hardware wallet manufacturer Trezor, the data of 67,000 US customers was exposed in a breach at its shipping provider, ShipMonk.
Trezor is an anonymous cryptocurrency hardware wallet that stores private keys separately from internet-connected devices. ShipMonk is one of its fulfillment partners, keeping records and handling customer shipments, which required access to names, addresses, phone numbers, and email addresses.
On Friday 4th September 2026, Trezor disclosed that a data breach involves 67,000 USA customers who ordered Trezor products between November 2019 and August 2021. This data includes:
- Names
- Email addresses
- Phone numbers
- Shipping addresses
- Order numbers
However, this incident is considerably larger than the one first reported on August 13. In that data breach, 11,742 customer names, emails, phone numbers, and shipping addresses were completely exposed. Also, 1,947 customers had partial exposure of name, city, and email, totaling about 13,689 people. All these records were connected to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026.
According to ShipMonk, attackers gained access by exploiting a vulnerability in the Metabase analytics platform. In August, Metabase notified the company that an unauthorized party used a software error to access the data. Reports claim that a critical SQL injection zero-day enabled attackers to get admin access on vulnerable instances. But the Trezor system was not breached, and its devices remain secure. Trezor wallet backups were and parcel contents were not leaked.
Trezor requires its shipping partners, including ShipMonk, to delete or anonymize order data within 90 days after delivery. Trezor said it repeatedly asked the company ShipMonk to confirm in writing that older records had been deleted. However, those records were still stored in its system.
The data of 67,000 US customers was exposed in this recent breach, bringing the overall impact above 80,000 customers. Trezor warns that this leaked data could be used for phishing scams and may also put customers at physical risk.
A scammer can impersonate Trezor, a bank, or a crypto exchange through emails, calls, or letters and trick people into sharing their recovery seed. Trezor has emailed affected customers from help@trezor.io. So, if you did not receive that message, it means you are not in the leaked data set.
However, if you get this email, you should be careful with urgent requests for your personal information. Always check with Trezor through its official channels, and never enter your wallet backup or recovery seed on a website or share it with anyone.
Trezor said this is the first time since 2013 that a security incident has exposed customer phone numbers and shipping addresses. The company is also working on an Anonymous Delivery option that will use locker pickup and automatically delete shipping data.