Trezor Data Breach Widens by 67,000 More Bitcoin (BTC) Wallet Customers
Trezor says 67,000 more US customers were exposed in the ShipMonk data breach, pushing the total above 80,000. Devices and seed phrases were not affected.
AI SummaryAI
- Trezor disclosed 67,000 additional US customers exposed in the ShipMonk data breach.
- Leaked records cover orders placed between November 2019 and August 2021.
- Total affected customers now exceed 80,000 across all disclosures.
- Trezor devices, systems and wallet backups were not compromised.
ShipMonk Kept Data It Promised to Delete
Hardware wallet manufacturer Trezor confirmed on Friday that a customer data breach first disclosed in August is substantially larger than originally reported. In an official statement posted on X, the Prague-based firm said an additional 67,000 customers in the United States had personal information exposed, including names, email addresses, phone numbers, shipping addresses and order numbers. Every newly affected record traces back to orders placed between November 2019 and August 2021. The update sharply expands the scope of the original incident: Trezor's August disclosure covered 11,742 customers spread across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, while a further 1,947 users saw a narrower slice of data — names, cities and email addresses — leaked. Taken together, the company now counts more than 80,000 affected customers. The breach did not originate in Trezor's own infrastructure. ShipMonk, the third-party fulfillment and shipping partner that handles order logistics for the wallet maker, experienced unauthorized access to systems containing customer data. What makes Friday's update pointed is Trezor's claim that ShipMonk had, throughout the commercial relationship, repeatedly provided written confirmation that customer records were deleted in line with the contract, Trezor's data policy and past communications — assurances the wallet maker says proved false. ShipMonk informed Trezor of the expanded scope on September 2, and the company says it has since emailed every affected customer directly. Trezor's parent company, SatoshiLabs, has been investigating the incident since the August disclosure. Neither company has publicly detailed how the retained records escaped the agreed deletion process.
official statement posted on Xhttps://x.com/Trezor/status/2095807665603584085?ref_src=twsrc%5Etfw
Seed Phrases and Devices Stay Safe
Trezor has stressed that its own systems, devices and customers' wallet backups were untouched, meaning no private keys or recovery phrases were compromised. The exposure concerns identity and logistics data, which does not grant any direct path to funds. The practical danger is targeted social engineering: armed with real names, phone numbers and home addresses tied to crypto purchases, attackers can craft convincing phishing emails, fake support calls or fraud messages far more credible than generic spam. The company's guidance to affected users is unambiguous — never enter a wallet backup or seed phrase into any website, and never share it with anyone, regardless of how legitimate a request appears. The episode echoes a familiar pattern among hardware wallet vendors, whose customer bases are high-value targets precisely because they demonstrably hold self-custodied assets. In 2020, rival manufacturer Ledger suffered unauthorized access to its e-commerce and marketing database, leaking more than 1 million email addresses and the personal contact data of nearly 10,000 customers — a breach that fueled years of phishing and even physical extortion attempts. Earlier this year, Ledger customers reported new notifications from Global-e, its payment partner, over a separate cloud-system breach of sensitive customer data. The risk stretches across retail finance: platforms that retain customer identity records, from self-custody vendors to brokers like Robinhood and payment partners such as PayPal, all carry the same third-party data-retention exposure. Privacy tooling such as the Mimblewimble protocol can shield on-chain activity, but no protocol protects a shipping address handed to a store in 2020. The same principle that keeps ASIC mining rigs and cold-storage devices safe — physical custody — does nothing for data sitting on a contractor's servers. Readers tracking the market in real time can follow live spot and futures prices on MEXC.
Phishing Is the Threat to Watch
COINOTAG's reading of Trezor's post-mortem is that this failure was contractual, not cryptographic. The official statement identifies the root cause plainly: ShipMonk retained customer records it had repeatedly certified as deleted, and the wider exposure surfaced only when the wallet maker audited its partner rather than trusting written assurances. The remediation is equally clear — direct email notification of every affected customer and explicit warnings against sharing seed phrases. For Bitcoin (BTC) holders, the enduring risk is no longer device security but the long tail of identity data on third-party logistics servers, where phishing — not key theft — is the attack vector to expect next.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


