Hardware wallet maker Trezor confirmed on September 4, 2026 that the data breach at its logistics partner ShipMonk is far larger than the company disclosed three weeks earlier, with roughly 67,000 additional US customers fully exposed. Bloomberg, which reported the update the same day, said the newly affected buyers placed orders between November 2019 and August 2021 and had names, email addresses, phone numbers and shipping addresses exposed. Trezor's original August 13 notice covered 13,689 people across seven countries. ETHNews and CybersecurityNews both put the combined total at more than 80,000; Trezor itself, in the X post quoted across the coverage, did not publish a consolidated figure. Note that none of the available sourcing is a regulator filing or CERT advisory: the confirmations trace back to Trezor's own X posts and blog updates, relayed through the press.
What Happened
The timeline runs in two stages. ShipMonk, which warehouses and ships Trezor products, told the company on Monday, August 10, 2026 that an unauthorized party had reached systems holding customer data. Trezor disclosed publicly on Thursday, August 13, describing an incident affecting customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal who received orders between May 10 and August 8, 2026.
The scope of that first disclosure is reported slightly differently depending on the outlet. BleepingComputer and CoinDesk both headline it as "nearly 14,000" customers, while Decrypt, Bitcoin.com and CryptoPotato give the precise figure of 13,689. The underlying breakdown is consistent across all of them and matches Trezor's own wording: 11,742 customers with full exposure and 1,947 with partial exposure. The apparent disagreement is rounding, not a factual conflict.
Trezor bounded that first disclosure using a data retention argument. The company requires fulfillment partners to delete or anonymize order data 90 days after delivery, which is why, per Decrypt and CryptoPotato, it expected older orders to be out of scope entirely.
That argument collapsed on September 4. Trezor said it had been told two days earlier that the leaked dataset also contained records from an earlier ShipMonk partnership spanning November 2019 to August 2021, fully exposing approximately 67,000 more US customers. ETHNews and CybersecurityNews both report that Trezor had repeatedly requested and received written confirmation from ShipMonk that those older records had been deleted, and that the records were nonetheless still present. CybersecurityNews additionally reports that an August 14 update had already conceded some partial-exposure records involved older orders, an early signal that the 90 day boundary did not hold.
What Was Taken
For the 11,742 customers in the August tranche: full name, email address, phone number and shipping address. For the other 1,947: name, city and email address. CryptoPotato reports that order numbers were included in the August set as well.
For the roughly 67,000 US customers added in September, ETHNews and CybersecurityNews list name, email address, phone number, shipping address and order number. Bloomberg's account of the same disclosure describes "full details" including names, emails, phone numbers and shipping addresses, without naming order numbers.
What was not taken is consistent across every source and worth stating clearly. Trezor's systems were not compromised. No private keys, recovery seeds, wallet backups or device data were involved, because that material never touches a fulfillment provider in the first place. CybersecurityNews adds that parcel contents were not exposed.
The sensitivity here is not in the technical depth of the data but in the correlation it enables. A verified home address tied to a confirmed hardware wallet purchase is a targeting list. Decrypt and CoinDesk both note that this is the first breach in Trezor's 13 year history to expose customer phone numbers and shipping addresses.
Why It Matters
Three things make this incident worth studying beyond the crypto sector.
First, the data class. Most consumer breaches leak credentials or contact details that fuel generic phishing. This one leaks physical location paired with a strong signal of stored-at-home value. CryptoPotato captured the customer reaction bluntly: replying to Trezor's phishing warning, an X user posting as Chikun wrote "Phishing?? They have physical addresses, you imbeciles," a comment the outlet says drew about 159 likes within the hour. Decrypt frames the same concern under the heading of "wrench attacks," the industry term for coerced key extraction through physical confrontation. The threat model for the affected population is not purely digital.
Second, the vendor deletion failure. Trezor had a contractual 90 day retention limit, asked for written confirmation of compliance, and received it. Half a decade of US order records sat on the provider's systems anyway, invisible to the company legally accountable for them. Attestation is not verification, and this incident is a clean case study in the gap between the two.
Third, the disclosure pattern. The August figure was presented as bounded and near final. It was wrong by a factor of roughly six. Any organization consuming vendor breach notifications should treat initial scope numbers from a third party as provisional until independently validated against their own records. ETHNews notes that Trezor publicly named ShipMonk's failure to honor the deletion commitment rather than absorbing it quietly, which is comparatively rare and gives downstream customers something actionable.
For sector context, CoinDesk cites SentinelOne data placing global breaches at an all-time high, up 17 percent versus 2025 at an average of 2,090 attacks per week worldwide, rising roughly 3 percent month over month since January. CoinDesk also situates the incident alongside earlier third party leaks affecting Trezor and rival Ledger, which produced long-running phishing and extortion campaigns.
The Attack Technique
Trezor did not explain how ShipMonk was breached. The technical detail comes from ShipMonk's own customer notifications and from security press.
BleepingComputer, which reviewed ShipMonk breach notification emails sent to affected customers, reports that ShipMonk attributed the intrusion to exploitation of a vulnerability in a third party platform. CybersecurityNews identifies that platform as Metabase, the open source business intelligence and analytics tool, and states that Metabase notified ShipMonk on August 6, 2026 that an unauthorized party had used a software flaw to reach account and customer data. CybersecurityNews further reports that later coverage tied the campaign to a critical SQL injection zero-day that granted administrator access on compromised Metabase instances.
That chain is worth tracing because it is the shape of the modern supply chain compromise: a flaw in an analytics layer, sitting downstream of the operational systems it reports on, holding a queryable copy of exactly the data a fulfillment provider processes. The attackers did not need to touch Trezor, and they did not need to touch ShipMonk's shipping infrastructure. They needed the reporting tool bolted onto it.
Note the sequencing. Metabase notified ShipMonk on August 6. ShipMonk notified Trezor on August 10. Trezor disclosed on August 13. The full US scope did not reach Trezor until roughly September 2, nearly four weeks after the initial vendor-of-vendor notification.
What Organizations Should Do
Verify vendor deletion instead of accepting attestation. A signed statement that data was purged is not evidence. Require cryptographic deletion certificates, sampled audit queries against live systems, or third party attestation with actual system access. Trezor asked the right question and got the wrong answer with no mechanism to detect it.
Inventory your fourth parties, specifically the analytics layer. Ask every processor which BI, observability and reporting tools hold copies of your data, who administers them, and how they are exposed. Metabase, and tools like it, routinely hold full-fidelity copies of production data outside the security perimeter designed around the production database.
Patch and harden self-hosted BI immediately. If you run Metabase or comparable platforms, confirm you are on a fixed version, restrict instances to internal networks or authenticated proxies, enforce SSO with MFA on all admin accounts, and constrain the database credentials the tool uses to read-only, minimum-scope access. Audit for anomalous administrative activity going back to at least early August 2026.
Treat third party breach scope numbers as provisional. Build the assumption of upward revision into your incident response plan. Do not send customers a "final" figure you cannot independently derive from your own records, and set internal review checkpoints for 30 and 90 days after any vendor-reported incident.
Enforce and monitor data minimization contractually and technically. A 90 day retention clause with no telemetry behind it is a document, not a control. Where feasible, push toward architectures where the provider never holds the sensitive field at all. Bitcoin.com reports Trezor is targeting an Anonymous Delivery capability for the EU by September 2026, which is the correct structural direction: remove the data rather than promise to delete it later.
Brief affected individuals on physical risk, not just phishing. For any breach exposing home addresses tied to high-value goods, the customer guidance should cover unsolicited in-person and postal contact, package interception and coercion scenarios. Trezor's standard guidance applies as a baseline: treat any message demanding immediate action as suspicious, verify through official channels only, and never enter a wallet backup on a website or share it with anyone, including support staff.
Sources: Trezor Crypto Wallet Data Breach Widens to 67,000 More US Customers... | Trezor discloses data breach affecting nearly 14,000 customers | Third-party breach exposes shipping addresses of 14,000 Trezor buyers | Trezor Customer Data Exposed in Shipping Partner Breach - Decrypt | Trezor Shipping Provider Exposes 13,689 Crypto Customers to Scams | Trezor Data Breach Hits 67,000 More Customers, Total Tops 80,000 -... | Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardw... | Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US C...