On 5 September 2026, Trezor disclosed that a breach at ShipMonk — the logistics provider that fulfils orders from its eShop — exposed the data of 67,000 US customers. A separate disclosure the previous month covered 13,689 more.
The records are names, email addresses, phone numbers, shipping addresses and order numbers, covering orders placed between November 2019 and August 2021.
ShipMonk told Trezor on 10 August 2026. Trezor disclosed on 5 September.
The part that should not have been possible
Trezor's own account of the retention arrangement:
Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.
And its stated policy: customer addresses and phone numbers are deleted or anonymised after 90 days.
Read those two facts against the date range. The oldest exposed records are from November 2019. Against a 90-day policy, that is data retained roughly twenty-eight times longer than the policy allowed, at a company that had confirmed in writing, more than once, that it no longer held it.
Trezor did the things a company is supposed to do here. There was a contract. There was a retention policy. There were repeated requests. There were written confirmations in response.
None of it was a control. A written assurance is a promise about a state of affairs, not a mechanism that produces it, and no customer of a third party can verify deletion from the outside. You can ask, you can contract, you can audit on a schedule — and between audits you are trusting a sentence in an email.
That is not a Trezor failure of process. It is the outer limit of what process can do, and it is worth being precise about, because the lesson people will take is "Trezor should have asked harder".
"Physical security risks" is not boilerplate here
Trezor's warning:
The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.
Most breach notices contain a sentence like that and most of the time it is legal padding. This one is not.
Reconstruct what the list actually is. Every person on it is someone who bought a hardware wallet — a device whose entire purpose is holding cryptocurrency offline — and every record pairs that person's name with their home address and phone number.
That is a target list for physical coercion. The pattern has a name in the industry and a growing case history, and it does not require the attacker to know how much anyone holds. It requires believing they hold something, which the purchase itself implies.
Phishing is the likely first use. It is not the worst one.
Two disclosures, one month apart, five times larger
13,689 in August. 67,000 in September. That progression usually means the scope assessment is still running, and it is a reason to treat the current number as a floor rather than a total.
The date range is also worth sitting with from the other direction. Records from 2019 to 2021 are five to seven years old. Many of those addresses are stale, which blunts the list. It also means people who have long since moved on from crypto — or who never told anyone they were in it — are on a document that says otherwise.
ShipMonk has said nothing
The company that held the data has made no public acknowledgement. Trezor, its customer, is doing the disclosing, the notifying and the explaining.
The same shape turned up last week in the Thomson Reuters C-Track notice, where the exposed material was described by one court as database copies handed to the vendor for troubleshooting. Different sector, identical failure: the breach was not at the company whose name is on the relationship, and the copy nobody governed is the one that leaked.
What to do
- If you bought a Trezor between November 2019 and August 2021, assume your address is out. Not your keys, not your seed phrase, not your funds — Trezor holds none of those and this breach does not touch them. Your address.
- Treat unsolicited contact about your wallet as hostile by default. The attacker now knows your name, your address, and that you own the device. That is enough to build a convincing letter.
- Nobody legitimate will ever ask for your recovery seed. Not Trezor, not support, not a courier, not a "security check". This is the phishing that this list enables and it will arrive.
- If you are a company: your vendors' deletion confirmations are not evidence. Ask when they were last verified rather than last asserted. Most organisations will find the answer is never.
- Reconsider what you send to fulfilment. A shipping label needs a name and an address. It does not need to persist for six years.
What is not established
- When the breach actually occurred. ShipMonk told Trezor on 10 August; the intrusion date has not been published.
- How long the data was exposed before discovery.
- What failed at ShipMonk. No technical detail has been released.
- Why the data still existed. Whether it was never deleted, deleted from one system and not another, or restored from a backup, is not stated.
- Whether the total is final. Two disclosures in, it is growing.