In an update issued on Friday, Trezor revealed that the data leak from its shipping partner, ShipMonk, was worse than previously believed. Specifically, the personal information, which includes names, addresses, phone numbers, email addresses, and order data, of another 67,000 users in the U.S. had been exposed.
Now, the total number of users whose data may have been compromised is 80,700. This makes holders with Trezor wallets at risk.
The new batch of data involves orders placed by U.S. customers between November 2019 and August 2021, as Trezor wrote in the post on X made on Friday.
Notably, some of that information is nearly seven years old. That is relevant because back in August, when Trezor announced the data leak, the 90-day data deletion policy implemented by its fulfillment partner was credited with limiting the number of impacted users.
The company explained that it had asked ShipMonk multiple times to provide documentation showing that the order data older than 90 days was deleted. Every time, the company received positive answers to those requests.
Now, Trezor expressed disappointment about the fact that those documents turned out to be incorrect. According to reports, Trezor placed the blame squarely on the shipping provider for keeping data it had promised to delete.
The new figures eclipse the old by a great deal. Back in August, Trezor estimated exposure to the breach to 14,000 people. However, ShipMonk reported findings to Trezor two days prior to its disclosure on Friday. That brings the tally up to around 80,700 users.
Two days ago, we received an update from our shipping provider, ShipMonk. We’re deeply saddened to share the news that the recent data breach affects more customers than originally thought.
Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S
— Trezor (@Trezor) September 4, 2026
Trezor clarified that its systems have not been compromised; no devices, private keys or wallet backups were exposed, as the breach was conducted purely from the logistics end. Information, such as customer contact details and shipping, was compromised.
The danger here lies in targeting. The leak of a mailing list with verified owners of hardware wallets, including the addresses where crypto users reside, lets hackers target those exact people for phishing attempts via email, phone calls and even snail mail.
Trezor advised the affected users to be wary of such attempts and also highlighted the threat to personal safety.
The threat is very real. In February, owners of Trezor and Ledger wallets received forged letters printed with holograms, QR codes, and even fake signatures of executives urging them to perform a fake security test or be locked out of their accounts.
As noted by cybersecurity expert David Sehyeon Baek, a forged letter delivered with a real name and address changes the psychology of the scam.
An impersonation scam does not necessarily require an exploit to steal from a user’s wallet. In fact, it is such scams that are already dominating cryptocurrency loss figures.
Blockchain cybersecurity firm Hacken found that phishing and social engineering scams made up $306 million of the $482 million total amount stolen within the first quarter of the year. One investor nearly lost $1 million by confirming a malicious token transaction on Ethereum in July.
Moreover, this is not the first time Trezor has faced a breach involving exposed user contact details. In January 2024, the company revealed that around 66,000 customers who have contacted its support team since December 2021 were exposed to phishing scams.
If you're reading this, you’re already ahead. Stay there with our newsletter.