A data breach at Trezor's shipping partner has grown far beyond its initial scope, with the hardware wallet maker confirming Friday that an additional 67,000 U.S. customers had their personal information exposed — bringing the total affected count to roughly 80,700 people. [1][2]

How the Breach Expanded

Trezor first disclosed the incident in August, estimating at the time that approximately 14,000 users had been caught in a breach at fulfillment provider ShipMonk. That figure rested partly on a 90-day data-deletion policy Trezor said it had negotiated into its contract with the company. [2]

That assurance has now collapsed. On September 4, Trezor announced it had received a new update from ShipMonk revealing that records belonging to an additional 67,000 U.S. customers — covering orders placed between November 2019 and August 2021 — had not been deleted as promised. [1][2] Some of those records are now close to seven years old. [2]

"Two days ago, we received an update from our shipping provider, ShipMonk," Trezor wrote in a post on X. "We're deeply saddened to share the news that the recent data breach affects more customers than originally thought." [2]

Trezor said it had repeatedly sought and received written confirmation from ShipMonk that the older records had been purged in line with its data policy — confirmation that turned out to be inaccurate. [1][2] The company said it was "disappointed" to learn otherwise. [2]

What Was Exposed

The compromised data includes full names, email addresses, phone numbers, home addresses and order-specific details. [1][2] Trezor's own systems were not penetrated, and the devices themselves, private keys and wallet backups remain untouched. [2]

The danger, however, is not technical — it is human. The exposed records identify confirmed hardware wallet owners at specific physical addresses, creating a rich target list for criminals who specialize in impersonation. [2]

The Threat Landscape: Phishing, Calls and Physical Letters

Trezor warned affected customers about risks on multiple fronts, including fake emails, fraudulent phone calls and forged physical letters. [2] The company stressed that a wallet seed phrase — the master backup controlling access to funds — should never be shared or entered into any website. [1]

The concern about physical mail is not hypothetical. Earlier this year, owners of both Trezor and rival hardware wallet Ledger were already receiving forged letters printed with holograms, QR codes and fake executive signatures, demanding recipients complete a fictitious security check or lose wallet access. [2]

Cybercrime consultant David Sehyeon Baek told Decrypt at the time that a letter carrying a name and home address sends a clear signal: "we can locate you." Baek also noted that stolen data retains its value for years because people rarely move or change their phone numbers. [2]

That observation is particularly relevant here, given that some of the newly exposed records date back to late 2019. [2]

The Technical Root Cause

The intrusion traces to a critical SQL injection vulnerability in the analytics tool Metabase, which was publicly disclosed on August 6. [2] The flaw allowed unauthenticated attackers to steal credentials for databases connected to the platform. [2] ShipMonk was not alone in being caught by this wave — laptop maker Framework and form builder Tally were reportedly affected by the same vulnerability. [2]

ShipMonk has reportedly received extortion emails attributed to the hacking group ShinyHunters, though that attribution has not been confirmed. [2]

Broader Industry Context

The breach arrives against a backdrop of surging social-engineering losses across the crypto industry. Phishing attacks and impersonation scams accounted for $306 million of the $482 million lost to crypto crime in the first quarter of this year alone, according to blockchain security firm Hacken. [1] In July, one crypto investor lost nearly $1 million after being tricked into signing a malicious token-approval transaction on Ethereum. [1]

Trezor itself has dealt with related incidents before. In January 2024, the company reported that around 66,000 users were at risk of phishing attacks following a separate incident involving its customer support system. [1]

What Trezor Is Doing

In response to the expanded breach, Trezor said it is working to roll out anonymous delivery as quickly as possible — an option that would allow customers to receive orders through locker pickup, with neutral packaging and generic sender details, eliminating the need to provide a home address at all. [2]

For now, affected customers — those who placed U.S. orders between November 2019 and August 2021 — should treat any unsolicited contact claiming to be from Trezor with extreme suspicion, whether it arrives by email, phone or post. [1][2]

What to Watch

The key questions going forward are whether ShipMonk's extortion situation leads to further data exposure, whether the ShinyHunters attribution is confirmed, and how quickly Trezor can make anonymous delivery a standard option rather than an emergency measure. Affected users should also monitor for targeted phishing campaigns in the coming weeks, as criminals typically act quickly once fresh contact data is in hand.