On Sept. 4 the size of Trezor’s data breach multiplied by roughly six, and the cause was about as unglamorous as security failures get: a vendor claimed the files had been erased, and they hadn’t been.
According to the hardware wallet manufacturer, the incident at fulfillment provider ShipMonk also exposed contact and order details belonging to a further 67,000 or so U.S. customers. Stack that on top of the 13,689 individuals Trezor named at the outset and the total lands near 80,689. The company has not published that combined figure, nor has it released row-level data indicating whether the two sets of customers overlap. The phrasing is what gives it away: by saying “another,” Trezor is treating these records as an addition to the first batch rather than a revised tally of it.
The records that were supposed to be gone
The freshly disclosed material relates to U.S. orders placed between November 2019 and August 2021 — names, email addresses, phone numbers, shipping addresses and order numbers.
Under Trezor’s own delivery-data policy, customer details are meant to be wiped from both its own systems and those of its fulfillment partner after 90 days, barring exceptions for order issues still being resolved. Instead, records dating to 2019 were still sitting in a vendor’s systems in 2026. Call that whatever you like; it isn’t a 90-day window off by a rounding error.
Trezor says it asked ShipMonk again and again to confirm the deletion, and again and again received written assurances that the data no longer existed. Those assurance letters have not been made public, and neither have the dates on them. That leaves customers with no way to verify when Trezor asked, what answer it got, or how far the paperwork had drifted from what was actually still on the server.
The first count was wrong twice
When Trezor disclosed the breach on Aug. 13, the figures it gave were both smaller and more precise: 11,742 customers fully exposed, 1,947 partially exposed. That initial account also stated that older order data had already been deleted.
A clarification issued Aug. 14 partly retracted that, conceding that some of the partially exposed records did in fact contain older orders. The Sept. 4 update undoes what was left.
Three separate disclosures, three separate pictures of one dataset. That is the predictable outcome when your grasp of an incident rests on a third party’s account of its own housekeeping.

How the data walked out
In a notification, ShipMonk traced the original unauthorized access to a flaw in the analytics platform Metabase. Metabase, for its part, said the August zero-day could generate a session bound to an administrator account and permit bulk downloads of tables.
An admin session combined with bulk export is roughly the cleanest route to an entire customer table that an attacker could hope for. Once the provider’s incident was reassessed, the historical data that had been retained pushed up the number of Trezor customers known to be caught in it.
Your keys are fine. Your address isn’t.
Trezor stated that its systems, products and services were not compromised and that its devices remained secure. What leaked is contact and order information. No recovery seeds, no private keys, no wallet funds.
Technically that distinction is real; practically it counts for a lot less. An ordinary leaked marketing list tells an attacker that you exist. This one ties a named individual to a physical address and to the knowledge that they purchased a hardware wallet — a fair proxy for holding crypto worth defending.
Trezor cautioned that the information could fuel persuasive scam emails, fraudulent phone calls or letters, and potential physical targeting. It is worth being exact about the level of certainty: the Sept. 4 update pointed to no confirmed downstream attack traced back to this dataset. These are risks, not documented outcomes. Nobody should read the update as proof that anyone has been robbed.

What to do if you ordered between 2019 and 2021
Every newly affected customer was emailed directly, Trezor said, and anyone who did not receive its incident notice was not caught up in the breach. Go check the address you used at checkout — including whichever inbox you had forgotten you were using five years ago.
The company’s guidance is the advice that has always applied, now urgent for a particular 67,000 people: never share a wallet backup, and never type one into a website. No legitimate support process is ever going to ask for it.
The awkward lesson here has nothing to do with cryptography. Trezor’s threat model did its job. The keys stayed on the device, the seed never left the customer’s possession, and the attacker walked away with nothing that unlocks funds. What broke was the humdrum paper trail that every physical product leaves behind on its way to a doorstep — held by a company Trezor does not operate, under a deletion policy nobody checked. Sell a device whose whole value proposition is that you need not trust anyone, and the shipping label is where that promise runs out.
















STAY ALWAYS UP TO DATE