The September update changes the scale of the breach

Trezor updated its security notice on September 4 after ShipMonk provided new information two days earlier.

The logistics provider said breached systems also contained records tied to approximately 67,000 additional U.S. customers who ordered products between November 2019 and August 2021.

Those records include names, email addresses, phone numbers, shipping addresses and order numbers.

Trezor says it has directly emailed the newly identified customers.

August’s disclosure was much smaller

The original incident notice on August 13 identified 11,742 customers with full exposure of name, email, phone number and shipping address.

Another 1,947 people had a more limited set of information exposed, including names, cities and email addresses.

That put the original total at roughly 13,689 affected customers. Adding the newly discovered group pushes the overall scope beyond 80,000 people.

The old records were supposed to have been deleted

This is the part that makes the September disclosure particularly awkward.

Trezor says customer order information is supposed to be deleted or anonymized 90 days after delivery. That retention window is intended to cover shipping, returns, refunds and replacements without preserving addresses indefinitely.

The company says it repeatedly requested deletion of the older ShipMonk data and received written assurances that the records had been removed in accordance with its contract and data policies.

Records dating back to 2019 were still present.

The Trezor devices were not breached

There is no indication that the attackers obtained wallet backups, recovery words or private keys through this incident.

Trezor says its own infrastructure was not compromised and that its hardware wallets remain secure.

That distinction prevents this from being described as a compromise of Trezor’s wallet security architecture. It does not make the exposed customer database harmless.

Personal data can become the first stage of a crypto attack

Scammers do not necessarily need to break encryption if they can persuade a user to reveal the recovery information voluntarily.

A message that knows a customer’s real name, phone number, order reference and shipping address can look considerably more credible than a generic phishing email.

Trezor is warning affected users about fraudulent emails, calls and physical letters, including attackers impersonating Trezor, banks or cryptocurrency exchanges.

Its core advice remains simple: never share a wallet backup and never enter it into a website.

Shipping addresses create an unusually sensitive dataset

Buying a hardware wallet does not reveal how much cryptocurrency somebody owns. It does indicate an interest in storing digital assets with dedicated security hardware.

Pair that information with a home address and the consequences extend beyond account phishing.

Trezor explicitly warns that the exposed information could create physical-security risks for affected individuals.

Crypto has seen this movie before

Ledger suffered a major customer-data breach in 2020 that eventually placed names, emails, phone numbers and some physical addresses into criminal circulation.

Customers continued reporting targeted scams, calls and letters long after the original incident.

Personal data has an inconvenient property that private keys do not: it cannot always be rotated.

Trezor is working on a more private delivery model

The company now recommends several ways to reduce the amount of identity data attached to a hardware-wallet purchase, including using a separate email address and, where practical, a P.O. box.

It is also developing an Anonymous Delivery option built around locker pickup, neutral packaging, generic sender information and automatic deletion of shipping identifiers after delivery.

Trezor currently plans to introduce that option in the European Union in September 2026 and in the United States by the end of the year.

Cold storage still has a supply-chain privacy problem

Nothing disclosed by Trezor suggests that ShipMonk gained access to the cryptographic material protected by the wallets.

The breach happened around the product rather than inside it: order processing, fulfillment and retention of delivery information.

For self-custody users, that boundary matters. Strong key protection solves one very specific security problem. A logistics database containing the owner’s name and home address is an entirely different one.