Trezor-ShipMonk breach hits 67,000 more US customers: 80,000 total

Share

Trezor has revised upward the scope of the ShipMonk breach: 67,000 additional US customers are now affected, bringing the total to over 80,000 exposed individuals. While devices remain untouched, the leaked personal data opens the door to targeted phishing and physical security risks.

🔑 Key takeaways

  • Total affected: over 80,000 customers, including 67,000 additional US users disclosed in September 2026
  • Forgotten data window: orders placed between November 2019 and August 2021
  • Breach source: ShipMonk, third-party logistics partner, via a Metabase flaw exploited by ShinyHunters
  • Wallets, recovery seeds, private keys and firmware: no compromise confirmed
  • Main risk: targeted phishing and increased physical threats to identified holders

Timeline of a worsening breach

The incident traces back to August 8, 2026, when an unauthorized actor exploited a vulnerability in ShipMonk’s Metabase deployment, the logistics provider’s analytics tool. ShipMonk notified Trezor two days later, on August 10, 2026. The first public statement followed on August 13, 2026, three days after the initial notification.

At that point, Trezor estimated that 13,689 customers were affected. Of those, 11,742 had their full information exposed (name, email, phone number, shipping address), while the remaining 1,947 only saw a partial subset of data compromised (name, city, email). The impacted order window ran from May 10 to August 8, 2026, covering customers based in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

Several outlets, including Forbes and Memeburn, attribute the intrusion to the ShinyHunters group, known for exploiting analytics tool flaws to reach third-party customer databases. Trezor’s 90-day data retention policy had, at that stage, limited the scope of the exposure — older data had been deleted from the logistics provider’s systems, at least on paper.

A 2019-2021 window ‘forgotten’ by ShipMonk

On September 2, 2026, ShipMonk informed Trezor that the breach also contained data from a previous partnership, covering orders placed between November 2019 and August 2021. This discovery added roughly 67,000 US customers to the list of affected individuals, bringing the total to over 80,000.

« We are deeply disappointed that, despite receiving this confirmation, the data was not deleted from their systems. »

Trezor, blog post dated September 4, 2026

Trezor says it repeatedly requested and received written assurances from ShipMonk confirming the data had been deleted, in line with the contract and privacy policy. Asked about the delay, the manufacturer said it had ‘no reason to expect this’ and added: ‘Our understanding is that our partnership from those years was overlooked when the original scope was established.’

A nearly doubled tally

Disclosure dateCustomers affectedTime window
August 13, 202613,689May 10 – August 8, 2026
September 2, 2026+ ~67,000 (US)November 2019 – August 2021
Estimated total> 80,0002019 – 2026

Trezor says it is too early to decide on potential measures against ShipMonk and that an additional audit of the logistics partner is being organized. ShipMonk, for its part, holds a SOC 2 Type II certification, an audited security standard recognized across the industry.

Wallets intact: risk shifts to the user

Trezor has reiterated it: neither its internal systems, nor the devices, nor customers’ wallet backups were compromised. No recovery seed, no private key, no firmware was touched.

« Scammers may use the leaked information to send fake emails, place fraudulent phone calls, mail fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor itself. »

Trezor official warning

The threat is therefore primarily human. The combination of a real name, a postal address, and confirmation that this person owns a hardware wallet gives attackers an ideal setup for spear-phishing and, in some cases, physical threats. According to CertiK, physical security incidents targeting crypto holders rose 33% in the first half of 2026, with about 52 cases reported worldwide. On the blockchain side, Hacken estimates phishing and social engineering accounted for $306 million of the $482 million stolen across the crypto industry in Q1 2026.

Extortion letters referencing actual Trezor orders have already been reported by several affected customers, according to media coverage of the case.

Context: a dark month for hardware wallets

The episode fits into a particularly rough stretch for the hardware wallet industry. On July 30, 2026, Coinkite, maker of the Coldcard, suffered a large-scale firmware exploit: roughly $116 million in bitcoin was drained directly from the affected devices, via a five-year-old random number generation flaw. TRM Labs called it the largest hardware wallet exploit of the year.

The comparison with the past is telling. In 2020, Ledger suffered an e-commerce database breach exposing around one million emails and 270,000 postal addresses — a reservoir that fueled years of phishing campaigns and several documented physical thefts. At the scale of the current case, the 11,742 complete addresses exposed by Trezor already exceed the roughly 9,500 Ledger buyers hit in the 2020 first wave, according to BeInCrypto. Combined with the near-identical breach suffered by SafePal in the week of August 17, 2026, more than 53,000 hardware wallet holders have been exposed via logistics partners over the period alone, Forbes estimates.

« Not a good month for hardware wallets. »

Changpeng Zhao, Binance co-founder, on X

Ashna Vaghela, chief customer officer at Mercuryo, summed up the sector’s mood: ‘While the Bitcoin industry is still absorbing the fallout from the Coldcard hack, the latest incident underlines how much trust can be shaken when attackers target the ecosystem around the wallet rather than the wallet itself.’

Financially, the market was not significantly affected: bitcoin continued to trade in a $60,000–$65,000 range for most of August 2026. The impact remains primarily reputational and behavioral.

Announced measures: anonymous delivery in the works

Trezor has apologized and detailed several recommendations to its customers: stay alert to any communication requesting immediate action, verify content through official Trezor channels, and never enter a recovery seed on a website. The manufacturer also advises using an anonymous email not tied to a real identity, paying in crypto rather than by credit card, and using a P.O. Box when possible.

The most visible workstream is the ‘Anonymous Delivery’ option: locker pickup, plain packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. It is slated for the European Union in September 2026 and for the United States by year-end.

« We are terribly sorry for everyone affected. We take this matter very seriously and are working to roll out anonymous delivery as soon as possible. »

Trezor, official communication

This is, according to Trezor, the first breach involving phone numbers and shipping addresses since the company was founded in 2013.


Conclusion

The Trezor-ShipMonk affair illustrates a structural vulnerability of the crypto ecosystem: the attack surface is not limited to protocols or wallets themselves, but extends to the logistics chain surrounding them. As long as shipping data sits with fallible third parties, the human link remains exposed.

For users, the lesson is twofold: on-device security remains solid, but pseudonymity is becoming a must. For the industry, the cluster of incidents (Coldcard, SafePal, Trezor) in just a few weeks is forcing a rethink of physical wallet delivery as a security problem in its own right. The coming quarters will show whether ‘Anonymous Delivery’ becomes a standard or remains the exception.

Sources

This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles