Scope of the Expanded Breach
Hardware wallet manufacturer Trezor has disclosed that a previously reported third-party data breach is significantly larger than initially estimated 12. On September 4, 2026, the Prague-based company announced that an additional 67,000 United States customers had their personal information exposed 12. This newly revealed leak includes sensitive details such as customer names, email addresses, phone numbers, physical shipping addresses, and order numbers 12. The compromised records belong to individuals who placed orders between November 2019 and August 2021, meaning some of the exposed data is nearly seven years old 12.
This expansion dramatically increases the scale of the incident. When Trezor first disclosed the breach in August, it reported that 11,742 customers across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were affected 1. Additionally, another 1,947 customers had their names, cities, and email addresses exposed 1. With the latest update, the total number of affected customers has risen from an initial estimate of 13,689 to approximately 80,700 2.
Supply Chain Failures and Deletion Policies
The breach did not compromise Trezor's internal systems, and the company confirmed that customer devices, private keys, and wallet backups remain entirely secure 2. Instead, the vulnerability lies within Trezor's supply chain, specifically involving its third-party shipping and fulfillment partner, ShipMonk 12. ShipMonk notified Trezor of the expanded breach two days prior to the September 4 announcement 12.
According to Trezor, the exposure occurred because ShipMonk failed to delete historical customer data as contractually required 12. Trezor stated that it had repeatedly requested and received written confirmation from ShipMonk verifying that the customer records had been deleted in accordance with their contract, data policy, and ongoing communications 12. Trezor had previously attributed the limited scope of the August disclosure to a negotiated 90-day data deletion policy with its fulfillment partners, a claim that has been undermined by these new revelations 2. Trezor expressed deep disappointment that ShipMonk maintained the records in its systems despite providing written assurances of their deletion 12.
Technical Origin and Attack Vector
The root cause of the data exposure has been traced to a critical security vulnerability in a widely used analytics tool 2. The intrusion stemmed from a SQL injection flaw in Metabase, which was publicly disclosed on August 6 2. This vulnerability allowed unauthenticated attackers to bypass security protocols and steal credentials for connected databases 2.
ShipMonk was not the only organization impacted by this vulnerability; other companies, including laptop manufacturer Framework and form builder Tally, were also affected by the same wave of exploits 2. Additionally, there are unconfirmed reports that ShipMonk received extortion demands linked to the cybercrime group ShinyHunters, though this attribution has not been verified 2. Neither Trezor nor ShipMonk immediately responded to inquiries regarding the specifics of the database compromise 1. Trezor's parent company, SatoshiLabs, stated that it was actively conducting an investigation into the incident 1.
Security Implications and Mitigation
The exposure of physical shipping addresses poses distinct security challenges for hardware wallet users. While digital assets remain secure on the devices themselves, the leak of physical addresses and names links specific individuals to cryptocurrency ownership 2. Trezor has warned affected customers of heightened risks, including targeted phishing campaigns via fake emails, phone calls, and physical letters 2.
Physical mail delivery has previously been used to target hardware wallet owners. In February, customers of both Trezor and its competitor Ledger reported receiving highly sophisticated forged physical letters 2. These letters featured realistic holograms, QR codes, and forged signatures of company executives, falsely instructing users to perform a mandatory security check to avoid losing access to their wallets 2. Cybercrime consultant David Sehyeon Baek noted that physical letters containing names and home addresses carry an implicit threat of physical location, adding that stolen contact data remains highly valuable to criminals for years because individuals rarely change their phone numbers or home addresses 2.
To mitigate these ongoing risks, Trezor announced it is working to implement anonymous delivery options 2. These options are intended to allow future buyers to complete purchases using locker pickups, neutral packaging, and generic sender details, eliminating the need to provide a home address 2.
What is not yet established
- Whether ShipMonk actually received extortion emails from the ShinyHunters cybercrime group
- The exact timeline for when Trezor will launch its anonymous delivery options
- The full extent of SatoshiLabs' ongoing investigation into the incident
Frequently asked questions
Were any private keys or wallet backups compromised in the ShipMonk breach?
No, Trezor's internal systems were not breached, and all devices, private keys, and wallet backups remain completely secure 2.
What specific customer details were leaked in the expanded breach?
The leak exposed the names, email addresses, phone numbers, physical shipping addresses, and order numbers of approximately 67,000 US customers 12.
How did the attackers gain unauthorized access to the customer data?
The breach was executed via a critical SQL injection vulnerability in the Metabase analytics tool, which was disclosed on August 6 2.
Sources
- Bitcoin Magazine — Trezor Breach Worse Than Reported: Another 67,000 US Customers Exposed (2026-09-04) https://bitcoinmagazine.com/news/trezor-data-breach-worse-than-reported
- Decrypt — 67,000 More Trezor Customers Exposed as Data Breach Widens (2026-09-04) https://decrypt.co/377389/67000-more-trezor-customers-exposed-as-data-breach-widens
This brief is for information and education. It is not financial advice or a recommendation to buy or sell.