[ Story · STORY ]

Trezor breach grows to 67,000 more US users

Trezor's ShipMonk breach jumps from 11,742 customers to nearly 79,000 after the vendor kept deleted data.

STORY·September 5, 2026·3 min read·By Gintautas Nekrosius
A cracked cream-colored shipping box spilling small red dots like scattered data points onto an empty surface
A vendor's broken promise, not a hack of the wallet itself.

Trezor told customers Friday that a data breach it disclosed in August is far bigger than first stated. An additional 67,000 US customers who ordered hardware wallets between November 2019 and August 2021 had names, emails, phone numbers, shipping addresses and order numbers exposed.

ShipMonk's broken promise

The new figures come from Trezor's third-party fulfillment partner, ShipMonk, which the company says had given written confirmation that customer data had been deleted. It hadn't.

  • Trezor's original August disclosure covered 11,742 customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal, per Trezor's announcement.
  • The Friday update adds 67,000 US customers with names, emails, phone numbers, addresses and order numbers leaked.
  • A further 1,947 customers had names, cities and emails exposed in the same update.
  • The exposed orders span a 21-month window, November 2019 through August 2021.
  • Trezor says it "repeatedly requested and received written assurance" of deletion from ShipMonk, per its own statement.

Total confirmed exposure now sits near 79,000 customers, roughly seven times the original count.

Vendor liability

The default read treats this as another hardware wallet security scare, filed next to Ledger's 2020 breach of a million email addresses. That framing misses where the failure actually sat.

Trezor's own devices and private keys were never touched. The exposure sits entirely in the shipping and fulfillment layer, a vendor holding retired records it was contractually required to erase and telling its client otherwise in writing.

That distinction matters for the incentive problem it exposes. Hardware wallet firms sell security as a product, but they still outsource logistics to third parties whose data retention practices are invisible until a breach forces disclosure.

Trezor had a signed deletion policy and written confirmations from ShipMonk and still ended up understating its own breach by a factor of seven. The written assurances were worth nothing once ShipMonk's systems were actually checked.

That's the part worth sitting with. A contract and a written confirmation didn't substitute for an audit, and the gap between "vendor says it's deleted" and "vendor actually deleted it" ran for years before anyone found out.

Fulfillment partners

Whether Trezor tightens vendor oversight, or whether this becomes a template for future disclosures, will show up in a few concrete places.

  • Whether Trezor names ShipMonk in a legal filing or discloses a contract penalty tied to the false deletion assurances.
  • Whether additional countries beyond the original seven report expanded customer counts in a follow-up statement.
  • Whether other hardware wallet makers using ShipMonk or similar fulfillment vendors issue their own disclosures in the coming weeks.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy