Shocking Trezor Breach Exposes 67,000 More US Customers Than Feared!

Hardware wallet manufacturer Trezor has revealed its recent data breach is far more extensive than initially reported, now affecting an additional 67,000 U.S. customers due to compromised data at its shipping provider, ShipMonk. The incident highlights recurring cybersecurity challenges for cryptocurrency users, reminiscent of past breaches at Ledger.
David Isong
David IsongCrypto8 hours ago2 minute read
Key Points
Trezor disclosed that its recent data breach is more extensive than initially reported, affecting an additional 67,000 U.S. customers.
The newly exposed data for these customers includes names, emails, phone numbers, shipping addresses, and order numbers from orders placed between November 2019 and August 2021.
The breach was attributed to ShipMonk, Trezor's third-party fulfillment partner, who failed to delete customer data despite assurances.
Shocking Trezor Breach Exposes 67,000 More US Customers Than Feared!

Hardware wallet manufacturer Trezor has announced that a data breach, initially reported last month, is far more extensive than first disclosed. The Prague-based company confirmed on Friday that an additional 67,000 U.S. customers had their sensitive information compromised. The leaked data for these customers includes names, emails, phone numbers, shipping addresses, and order numbers, stemming from orders placed between November 2019 and August 2021.

This expanded revelation follows Trezor's initial announcement in August, which detailed that 11,742 customers from the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal were affected. That initial breach exposed names, emails, phone numbers, and shipping addresses. In the latest update, a tweet from Trezor dated September 4, 2026, confirmed the significantly increased scope, stating, "We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…" Furthermore, an additional 1,947 customers had their names, cities, and emails exposed in the breach.

The root cause of the breach has been attributed to ShipMonk, Trezor's third-party fulfillment partner. Trezor expressed profound disappointment, revealing that despite repeated requests and written assurances confirming the deletion of customer data in accordance with their contract and data policy, ShipMonk had failed to delete the information from their systems. Trezor had previously reported in August that ShipMonk experienced "unauthorized access to their systems containing customer data."

Trezor has taken steps to directly email all customers affected by the breach, and its parent company, SatoshiLabs, is actively investigating the incident. Neither Trezor nor ShipMonk has responded to inquiries regarding the breach.

This incident underscores a broader pattern of cybersecurity vulnerabilities within the cryptocurrency hardware wallet industry. A notable precedent is the 2020 breach involving Ledger, another popular hardware wallet manufacturer, where an unauthorized party accessed its e-commerce and marketing database. This resulted in the leakage of over 1 million email addresses and the personal contact data of nearly 10,000 customers. More recently, at the start of the current year, customers reported receiving emails from Global-e, Ledger’s payment partner, concerning a data breach within its cloud systems that exposed sensitive customer information.

Loading...