CASABLANCA, September 5, 2026
Trezor said Friday that a breach at shipping provider ShipMonk exposed another 67,000 U.S. customers, including years-old orders the wallet maker says should have been deleted, widening a privacy incident as Bitcoin traded near $80,000.
The newly identified group bought between November 2019 and August 2021. Their names, email addresses, phone numbers, shipping addresses and order numbers were exposed, according to the company, which says its own systems and devices were not compromised.
At the market-data check early Sept. 5, CoinGecko listed Bitcoin near $79,642, with a market value around $1.6 trillion and approximately $34.3 billion in 24-hour trading volume. Those figures provide broader market context; the available evidence does not establish a price response to the disclosure.
In its Sept. 4 public follow-up, Trezor said ShipMonk had repeatedly supplied written assurances that the records were deleted. The company now says those assurances did not match the information retained in the provider’s systems.
The update expands the 13,689-customer exposure reported in August to approximately 80,700 people. It changes the affected purchase period and calls the deletion controls into question, rather than simply rounding up an existing count.
As of 02:10 UTC on Sept. 5, this review found no independently verified crypto-theft total, drained-wallet count or on-chain transaction evidence attributing losses to this ShipMonk incident. Customer reports of suspicious contacts warrant attention, but they do not establish that the newly exposed records have produced confirmed wallet thefts.
Bitcoin
BTCSource: CoinGecko Bitcoin market data. Daily observations and the latest intraday reading; market prices do not measure the breach’s financial impact.
Trezor’s older orders widen the ShipMonk breach
The original incident notice said ShipMonk informed Trezor of unauthorized access on Aug. 10. It identified 11,742 customers with full contact-data exposure and another 1,947 with partial exposure, initially pointing mainly to recent deliveries in seven countries.
Trezor subsequently warned that the partial-exposure group might include older orders. Friday’s announcement goes substantially further: it identifies a separate, much larger U.S. group from several years earlier. The approximate combined total reflects the company’s description of these customers as additional.
The distinction is consequential for anyone who bought a device long ago and assumed the August warning applied only to recent shipments. A customer-data exposure can persist beyond the life of a purchase because an address or phone number may remain useful to an impersonator for years.
Trezor’s published data-retention policy says delivery information is deleted from its systems and those of fulfillment partners after 90 days, subject to exceptions for unresolved order issues. It separately describes longer retention periods for invoices and payment records.
Those are different categories of information. Keeping an invoice in a separate encrypted environment does not, by itself, explain why old names, telephone numbers and home addresses remained available in a shipping provider’s systems. The unresolved question is how the deletion process was checked against the assurances Trezor received.
Trezor told Protos it is arranging an additional audit of ShipMonk and that it is too early to decide its response to the provider. It said its understanding was that the earlier years of cooperation had been overlooked when investigators established the original scope.
Phishing reports do not establish a wallet-loss total
An exposed delivery record can help a scammer impersonate support without giving that scammer a private key. The danger is persuading a customer to supply the missing secret or authorize a transfer, which is different from remotely breaking the hardware wallet.
A Sept. 4 customer post described receiving a fake Trezor letter containing a QR code. The writer reported an older purchase and several subsequent moves; the post did not establish where the sender obtained the address or report a quantified theft.
That evidence supports reporting a suspicious-mail account, not attributing an attack wave to the expanded dataset. No corroborated aggregate of financial losses was identified in the company disclosures, security reporting or public victim accounts reviewed for this article.
The underlying vendor intrusion does have a documented technical context. BleepingComputer reported from ShipMonk notification emails that attackers exploited the provider’s Metabase analytics software. Metabase’s own Aug. 6 security notice described an exploited flaw that could grant administrative access and enable data exports.
Patching that software addresses the entry point; it cannot retrieve copies of information already taken. The customer-data risk also resembles the separate SafePal order-information exposure, where contact records created an impersonation risk without being a wallet backup.
Trezor audit and anonymous delivery remain next steps
Trezor says it has emailed affected customers directly. Anyone uncertain about an order can use Trezor’s support website independently, rather than following a link or telephone number supplied in an unsolicited message.
Its anti-phishing guidance warns that professional-looking messages, calls and websites can impersonate support. A request for a wallet backup, PIN or other secret is a warning sign, even if the sender already knows accurate purchase details.
The company advises users never to disclose their wallet backup or type it into a website. Threats that a device will be deactivated unless its owner completes a verification step are another documented impersonation tactic.
Trezor has also described plans for anonymous delivery using locker collection, neutral packaging and deletion of shipping identifiers after delivery. Its August notice targeted the European Union for September and the United States by year-end; the follow-up did not announce a completed rollout.
Broader crypto sentiment remained in greed territory: Alternative.me’s index showed 73 out of 100 at the research check. That market indicator says nothing about the safety of a particular message or the extent of customer-data exposure.
Fear & Greed Index
September 5, 2026The next substantive developments are the additional audit’s findings, any further changes to the affected order periods, and evidence connecting stolen records to specific fraud losses. Until those emerge, the expanded customer count and disputed deletion assurances are the confirmed change, with the audit outcome and financial impact still unresolved.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Trezor: September 4 customer-data breach follow-up |
| | Trezor: Original ShipMonk incident notice |
| | Trezor: Privacy and data-retention policy |
| | Metabase: August 6 security update |
| | Trezor: Scams and phishing guidance |
| | CoinGecko: Bitcoin market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How many Trezor customers are affected by the ShipMonk breach?
Trezor added about 67,000 US customers to the 13,689 previously disclosed, putting the reported total near 80,700. This is a customer-data count, not a count of drained wallets.
Which older Trezor orders were exposed?
The September 4 update identifies US orders placed between November 2019 and August 2021. Trezor says names, emails, phone numbers, shipping addresses and order numbers were exposed.
Were Trezor recovery phrases or funds stolen in this breach?
Trezor says its systems and devices were not compromised. As of 02:10 UTC on September 5, this review found no independently verified theft total, drained-wallet count or on-chain loss attribution tied to the ShipMonk incident. Phishing reports do not establish a confirmed loss.
What should affected Trezor customers do?
Verify notices through Trezor's official support website. Do not share a wallet backup or enter it into a website, and treat unsolicited calls, messages and letters requesting wallet action as suspicious.



