Another 67,000 Trezor customers had their names, email addresses, phone numbers, home addresses and order numbers exposed in the breach at ShipMonk, the company responsible for shipping logistics, the hardware wallet maker disclosed on Friday.
All affected customers are in the US and placed orders between November 2019 and August 2021, meaning some of the exposed records date back nearly seven years. ShipMonk reported the discovery two days earlier.
Trezor said it had repeatedly requested and received written confirmation that these records had been deleted — in line with its contract and data policy — and said it was disappointed to learn this had not happened.
When it disclosed the breach in August, the company attributed the incident's limited scope to a 90-day deletion policy it said it had negotiated in its contractual terms with logistics partners. That claim now looks considerably weaker. The number of people affected jumped from 13,689 to roughly 80,700.
Wallet owners face multiple threats
Trezor's own systems were not breached; devices, private keys and wallet backups remain intact. The danger lies in the fact that the records identify confirmed hardware wallet owners tied to specific home addresses. Beyond fraudulent emails, calls and letters, Trezor warned affected customers about risks to their physical safety and reiterated that a wallet's backup should never be shared or typed into a website.
Owners of Trezor wallets and those of its competitor, Ledger, had already been receiving fake letters back in February — featuring holograms, QR codes and forged executive signatures — demanding activation of a bogus security check under threat of losing access to their wallets.
At the time, cybersecurity consultant David Sehyeon Baek told Decrypt that a letter containing a person's name and home address signals "we can find you," and that stolen data remains useful for years, since people rarely change homes or phone numbers.
The breach originated in a critical SQL injection flaw in the Metabase analytics tool, disclosed on 6 August, which allowed unauthenticated attackers to steal credentials from connected databases. Laptop maker Framework and form-building platform Tally were also hit by the same wave of attacks. ShipMonk reportedly received extortion emails attributed to the ShinyHunters group, though this attribution has not yet been confirmed.
Trezor said it is working to make an anonymous delivery option available as soon as possible — using pickup at smart lockers, plain packaging and generic sender details — so that buyers do not need to provide their home address.
* Translated and edited with permission from Decrypt.
Your gateway to bitcoin, the world's largest cryptocurrency, is MB. It's simple, secure and transparent. Stop putting off an investment with huge potential. Invest in just a few clicks!




