SOCLYDE logo
Current languageEN
Cybersecurity newsData breachService providersCrypto assets

Trezor shipmonk breach: 81,000 customers exposed

The ShipMonk breach ultimately affected 80,689 Trezor customers. Here is what shipping data retention means for crypto-holder targeting.

By Soclyde Editorial Team

Fulfillment station with parcels and retained order archives

In summary

  • Trezor says 80,689 customers are affected by the breach at logistics provider ShipMonk.
  • The exposed data concerns orders and delivery; Trezor devices, wallet backups and private keys are not reported as affected by Trezor.
  • The main risk is highly personalized phishing, with an additional physical-security concern when a hardware-wallet purchase can be tied to a person and address.

Explore next

Soclyde resources

Article contents

The update published by Trezor on September 4, 2026, and widely covered on September 7, changed the scale of the ShipMonk incident. The storage and fulfillment provider was first linked to 13,689 customers; Trezor now says 80,689 people are affected after adding about 67,000 US customers whose orders dated back to 2019–2021.

This is not an account of access to Trezor devices or to the funds held by their owners. It does show what a logistics chain can reveal: an address, phone number and hardware-wallet purchase history create enough context to make a scam credible and, in some cases, to identify where a person may live.

What happened at ShipMonk

ShipMonk, one of Trezor's shipping providers, told the company on August 10, 2026, about unauthorized access to systems containing customer data. Trezor published an initial notice on August 13: 11,742 customers had full exposure of their name, email, phone number and shipping address; another 1,947 had exposure limited to name, city and email.

In customer notifications, ShipMonk attributed the access to a vulnerability in its Metabase analytics platform, based on the notification reviewed by BleepingComputer. Trezor has not published additional technical detail in its notice and describes the investigation as ongoing. The established point is therefore the most useful one: the access occurred in the logistics provider's environment, not in Trezor's systems.

Why the scope reached 80,689 customers

On September 2, ShipMonk told Trezor that the stolen data also included orders from an earlier partnership, between November 2019 and August 2021. Trezor's September 4 update added about 67,000 US customers to the people already identified, bringing the announced total to 80,689.

Trezor says it repeatedly requested deletion and received written confirmations that the information had been removed. The company nevertheless says the older data was still present in ShipMonk's systems. That is the central lesson: a contractual retention rule reduces risk only when it is checked in the systems actually operated by the supplier.

The fields listed for the newly acknowledged group are name, email address, phone number, shipping address and order number. The 80,689 figure comes from Trezor; it is not an independent record-by-record audit and does not mean every customer was individually attacked.

Shipping data can identify a crypto-asset holder

An address alone does not reveal how much value may be stored in a home. In this case, however, it is tied to a Trezor order number and a product associated with self-custody of crypto assets. Combining identity, phone number, home address and purchase history makes a fraudulent message more convincing than a generic campaign.

Trezor warns that the data could support fraudulent emails, calls or letters impersonating Trezor, a bank or an exchange. It also mentions physical-security risk. That does not prove that a physical intrusion is planned or that a wallet still holds funds; it means the published information justifies extra, discreet caution.

Parcel contents, wallet backups and private keys are not reported as exposed. The breach therefore mainly improves the targeting of a later attempt to request a recovery seed, code or transfer—three requests a legitimate service must never make.

What Trezor customers should do

If you received a Trezor notification, keep it but verify its contents by opening trezor.io or the official app yourself. Do not click an email, text-message or letter link to “secure” a wallet, confirm an address or move funds. Trezor says affected customers were contacted directly; do not replace that process with a self-report on a third-party website.

Never share a recovery seed or enter it on a website, even if the message includes your name, former address or an exact order number. Enable multi-factor authentication where available on your email account and exchanges. If a reused password is linked to the exposed email address, change it first on email, then on financial and work accounts.

Also limit public information that connects your name to an address or a wallet. If a call or letter mentions your Trezor purchase and demands urgent action, end the exchange and verify through a separately opened channel. Trezor says it is preparing an Anonymous Delivery option with locker pickup, neutral packaging and automatic deletion of shipping identifiers; that future option does not undo the historical exposure.

What companies should review with suppliers

The ShipMonk incident shows that a supplier is not only an operational executor: it becomes a temporary custodian of data describing customers, addresses and purchases. A clause requiring deletion after 90 days is not enough if older databases, exports, backups or analytics tools are outside the check.

Companies outsourcing fulfillment should map the fields they transmit, the tools that replicate them and the people who can access them. They should request evidence of deletion, review service accounts and document access revocation. For products that can signal an interest in crypto assets, data minimization and neutral shipping deserve particular attention.

Response planning should also include customer notification and an independent verification channel. In the Trezor case, the useful response is not to change firmware or move funds automatically; it is to prevent a fraudulent request that uses accurate logistics details.

Soclyde does not protect ShipMonk, Trezor or data already exposed, and it cannot undo this breach. Its role is complementary: generate a different secret for each account, store it in a local-first encrypted vault and quickly identify access that needs rotating when an email address or related service becomes a target.

That separation keeps a shipping-data leak from becoming an email or financial-account compromise through password reuse. It does not replace caution around unsolicited messages or protection of a recovery seed, which must remain offline and secret.

Key takeaways

The Trezor ShipMonk breach ultimately affected 80,689 customers according to Trezor, combining the first 13,689-person scope with about 67,000 older US orders retained beyond the expected period. The data concerns order and delivery; devices, backups and recovery keys are not reported as compromised.

Verify every alert through an official channel opened manually, never share a recovery seed and remove password reuse. To structure that rotation, read the secure password generator guide or contact Soclyde.

Frequently asked questions

Am I affected by the Trezor ShipMonk breach?

Trezor says affected customers were contacted directly by email. The September expansion adds about 67,000 US customers who ordered between November 2019 and August 2021; the first scope covered 13,689 customers in seven countries. Verify any notice by typing trezor.io yourself instead of using an unexpected link.

Are bitcoin or my recovery seed exposed?

Trezor says its systems and devices were not compromised, parcel contents were not exposed and wallet backups are not part of the disclosed data. Never enter a recovery seed on a website or share it with anyone, regardless of how convincing a message looks.

Why was an old delivery address still retained?

Trezor says it repeatedly requested deletion and received written assurances from ShipMonk. The company says US orders from November 2019 to August 2021 were nevertheless still present in the provider's systems, despite its policy to delete or anonymize data after 90 days.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading