Trezor, the hardware wallet maker, says the data breach at its shipping partner ShipMonk now reaches roughly 81,000 customers, about six times the number it first announced. The newly discovered records are order data from 2019 to 2021 that should already have been deleted. Devices and private keys are untouched, but for people who hold their own crypto, having names and home addresses exposed together is not a small matter.

The Leak Started in August, Behind the Shipping Counter

It began on August 10, when ShipMonk, Trezor's logistics partner, reported unauthorized access to systems holding customer data. ShipMonk stores Trezor products and ships them to several countries including the United States and the United Kingdom, and it held the names, addresses, phone numbers and email addresses needed to deliver a parcel.

When Trezor disclosed the incident on August 13, the count stood at 11,742 customers with full exposure of name, email address, phone number and shipping address, plus 1,947 customers whose exposure was limited to name, city and email address. The affected orders were those received between May 10 and August 8 in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. The scope was narrow because Trezor deletes or anonymizes order data 90 days after delivery and requires its partners to do the same.

Data That Was Supposed to Be Gone

On September 2, however, ShipMonk reported that the breach was larger than first stated. The stolen trove also contained order records from an earlier period of cooperation between the two companies, running from November 2019 to August 2021. Trezor published the finding on September 4, saying roughly 67,000 additional customers in the United States had their names, email addresses, phone numbers, shipping addresses and order numbers fully exposed. That is a 479 percent increase over the original estimate.

Trezor is unusually blunt about this point. Throughout the relationship it repeatedly asked for deletion and received written confirmation that the data had been removed in line with the contract and its data policy, yet the records were still there. The company says it is weighing legal action. ShipMonk has reportedly secured the affected systems and hardened its security.

Devices Are Fine; the Risk Lies Elsewhere

The first thing to be clear about is that only contact details used for delivery were exposed. Trezor's own systems were not compromised, and the hardware wallets, private keys and wallet backups are all unaffected. Nothing that identifies the contents of a parcel was included either.

Even so, the fact that names, home addresses and phone numbers of people who bought crypto storage hardware leaked as a single set deserves to be taken seriously. Trezor's first warning is about more convincing phishing. Emails, phone calls and physical letters may arrive impersonating banks, exchanges or Trezor itself, and back in 2022 the company had to warn customers about a fake breach notification aimed at them. It also points to the physical security risk that comes with a known address.

Affected customers were notified individually from a dedicated address, and Trezor says that anyone who did not receive that email is not affected. Going forward, the advice is to treat any message that pushes for urgent action with suspicion, and above all never to type a wallet backup into a website or share it with anyone.

Anonymous Delivery, Moved Up

Trezor says this is the first time since the company was founded in 2013 that customer phone numbers and shipping addresses have been exposed. Its answer is to reduce the amount of personal data that leaves the company in the first place.

The anonymous delivery option now in preparation combines a dedicated checkout, locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers once delivery is complete. The targets are September 2026 in the European Union and the end of 2026 in the United States, and the company says the incident has pushed it to accelerate the work. Until then it suggests using a P.O. box, a parcel locker or a pickup point, ordering with an email address not tied to a real identity, and paying with crypto or disposable digital cards.

To buy a product designed to keep your keys under your own control, you have to hand an address and a phone number to a third-party warehouse operator. That structural twist is what this incident put on display most clearly. Shipping a physical product means the data can never be zero, but shorter retention and a better-designed handoff can change how much of it is ever at risk.

Summary

The breach at Trezor's shipping partner ShipMonk has grown from about 13,700 customers to roughly 81,000. The additional records are order data from November 2019 to August 2021 that was supposed to have been deleted, exposing names, email addresses, phone numbers, shipping addresses and order numbers in full. Wallets and private keys are safe, but the phishing and address-related risks remain. Trezor is accelerating its anonymous delivery option, targeting September 2026 in the European Union and the end of 2026 in the United States.