Trezor ShipMonk Data Breach Expands, Exposing Over 80,000 US Customers
Hardware wallet maker Trezor confirmed a data breach at its logistics partner ShipMonk has exposed an additional 67,000 US customers, bringing the total affected to over 80,000.

Hardware wallet manufacturer Trezor has announced that a data breach affecting its logistics partner, ShipMonk, is significantly larger than initially reported. The incident now encompasses older U.S. order records, exposing approximately 67,000 additional customers.
This expanded breach stems from order data related to a prior ShipMonk partnership between November 2019 and August 2021. Trezor was informed of this expanded scope on September 4, 2026, two days after ShipMonk initially reported unauthorized access on August 10. The initial disclosure on August 13 covered 13,689 customers whose data was exposed between May 10 and August 8, 2026, across several countries.
ShipMonk identified that attackers exploited a zero-day SQL injection vulnerability within its Metabase analytics platform. This flaw allowed unauthorized parties to gain access to account and customer data. Metabase itself had notified ShipMonk of the software flaw on August 6, leading to the discovery of the breach.
Trezor has emphasized that its own systems were not compromised, and the security of its hardware wallets and backups remains intact. The contents of customer parcels were also not exposed in this incident.
The newly exposed U.S. customer data includes names, email addresses, phone numbers, and order numbers. Trezor warns that this combination of personal information, including home addresses and purchase history, poses a significant risk for targeted phishing campaigns and potential physical security threats.
In response to the expanded breach, Trezor is advising affected customers to be vigilant against phishing attempts and to verify any urgent requests for personal data through official Trezor channels. They also reiterated the importance of never entering wallet recovery seeds into websites or sharing them with anyone.
This incident marks the first time since Trezor's founding in 2013 that customer phone numbers and shipping addresses have been exposed. The company is accelerating plans to introduce an Anonymous Delivery option, which will include locker pickup and automatic deletion of shipping identifiers.
Trezor stated that it had received written assurances from ShipMonk regarding the deletion of older order records, making the continued presence of this data in ShipMonk's systems particularly concerning. The company is implementing stricter oversight of its fulfillment partners' data handling practices.