Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found

BlockchainSeptember 5, 2026·5 min read

Hardware wallet maker Trezor disclosed that a breach at its logistics provider ShipMonk exposed approximately 67,000 additional U.S. customers, six times the initial count, after supposedly deleted shipping records from 2019 to 2021 remained in the vendor’s systems despite written assurances of deletion. The incident expands institutional custody and consumer protection risks in an ecosystem where hardware wallets have become central to asset security strategies, and raises questions about third-party data retention practices across the blockchain infrastructure stack.

  • Trezor’s disclosed exposure expanded from 13,689 to roughly 80,689 customers after logs deleted per policy remained at ShipMonk for years.
  • Exposed data spans November 2019 through August 2021 and includes names, emails, phone numbers, addresses and order numbers, linking individuals to hardware wallet purchases.
  • Trezor received written deletion assurances from ShipMonk multiple times, yet records persisted; the breach originated from a Metabase analytics platform zero-day vulnerability.
  • 67,000 Additional U.S. customers exposed in Sept. 4 update versus initial August disclosure
  • 80,689 Approximate total customer count exposed across both disclosure periods combined
  • 90 days Trezor’s stated data retention policy window before deletion from partner systems

On September 4, Trezor announced a significant revision to its August 13 disclosure of a security breach at ShipMonk, its third-party logistics provider. The new update revealed that approximately 67,000 additional U.S. customers had been exposed, a figure that dwarfs the originally disclosed 13,689 affected users and brings the total known exposure to roughly 80,689 people.

The breach exposed contact and order information spanning November 2019 through August 2021, including names, email addresses, phone numbers, shipping addresses and order numbers.

Critically, the newly discovered records had persisted in ShipMonk’s systems despite Trezor’s written deletion requests and the company’s stated 90-day data retention policy, which requires customer information to be purged from both Trezor and partner systems after that window expires.

Trezor received written deletion assurances that ShipMonk failed to honor for years

The breach represents a stark failure in third-party data governance. Trezor stated that it had “repeatedly requested and received written assurances” that ShipMonk had deleted historical customer records, yet the vendor retained data going back to 2019, nearly six years before the breach discovery.

Trezor’s published delivery-data policy explicitly commits to a 90-day deletion window, with limited exceptions for ongoing order fulfillment issues. The company did not disclose the dates of the assurance letters ShipMonk provided or publish the correspondence itself, leaving unclear how frequently Trezor verified compliance or what triggered the discovery that the deletions had never occurred.

The incident compounds institutional custody risks at a moment when large asset managers and financial institutions have begun integrating hardware wallets into qualified custody workflows. A breach that exposes physical addresses linked to hardware wallet purchases creates attack surface unavailable in conventional securities infrastructure.

Trezor emphasized that the breach did not compromise wallet cryptographic material, no recovery seeds, private keys or wallet funds were exposed, and that the company’s devices and systems remained secure.

The risk instead emanates from the peripheral data: the connection between an identified individual, a physical location and a confirmed hardware wallet purchase can inform convincing social engineering, fraudulent communications or physical targeting.

Trezor acknowledged that the exposed information could support scam emails, fraudulent calls or letters and potential physical targeting.

Metabase zero-day vulnerability opened ShipMonk’s systems to unauthorized access

According to BleepingComputer reporting, ShipMonk’s breach originated from an unpatched vulnerability in Metabase, an open-source analytics platform. The August zero-day flaw allowed an attacker to create a session tied to an administrator account and execute bulk table downloads without authentication.

This attack vector gave an unauthorized actor direct access to ShipMonk’s historical order database, exposing records that should have been purged years earlier under Trezor’s contractual retention policy. The vulnerability represented a known security risk in a widely deployed analytics tool, underscoring the cascade effect when third-party vendors fail to patch critical infrastructure.

The distinction between Trezor’s systems and ShipMonk’s infrastructure is crucial for institutional risk assessment. Trezor’s own systems, products and services were not compromised, and the security of devices themselves remained intact.

However, the vendor relationship created a trust assumption that proved unfounded: Trezor relied on ShipMonk’s adherence to data deletion practices, monitoring and security posture without publishing the contractual terms, audit frequencies or remediation timelines that would normally govern such arrangements.

The expanded disclosure suggests Trezor did not discover the data retention failure through its own audit but rather through ShipMonk’s post-incident investigation or external security review after the Metabase vulnerability was exploited.

The breach did not reach Trezor’s wallet systems, and devices remained secure; the risk centers on the peripheral identity and physical location data.

No confirmed downstream attacks documented, but physical targeting risks remain open

As of the September 4 update, Trezor reported no confirmed downstream attacks using the exposed dataset. This absence does not eliminate the risk: datasets linking identifiable individuals to high-value asset infrastructure typically attract targeting by organized crime, fraud rings and state-level actors.

The data’s composition, names, addresses, phone numbers and explicit hardware wallet purchase records, creates a targeting list of known asset holders, a category substantially more valuable than generic contact databases or email leaks that trade in underground forums at single-digit dollar costs per thousand records.

The institutional implications extend beyond individual customer risk. Regulated entities integrating Trezor or other hardware wallet solutions into custody infrastructure must now factor third-party logistics and data retention failures into their vendor risk assessments.

The incident demonstrates that even companies with published data policies and contractual safeguards cannot guarantee compliance from partners without rigorous verification, audit trails and financial penalties for non-compliance.

For asset managers and financial institutions currently evaluating hardware wallet custody solutions, the Trezor-ShipMonk incident provides a case study in the operational complexity and third-party dependencies that peripheral custody solutions introduce compared to fully managed, regulated custodians.

Trezor has not disclosed whether the 13,689 originally affected users and the 67,000 newly disclosed users represent entirely separate populations or whether there is overlap between the groups.

The company’s use of the phrase “another approximately 67,000” suggests it considers the new figure additional, but without published data or group analysis, institutional investors cannot determine the true scope of customer exposure or assess whether their own address data appears in either disclosure.

Trezor has not published the underlying data, the assurance letters from ShipMonk, or a clear accounting of how many total unique customers were exposed across both disclosure periods, leaving institutional counterparties unable to independently verify customer risk exposure or conduct their own impact assessments. The company’s next disclosure should include the specific dates of ShipMonk’s deletion assurances, the audit frequency Trezor employed to verify third-party compliance, and a consolidated customer count with overlap analysis to enable informed custodial decisions.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe