Crypto: Trezor Data Breach Expands to 67,000 More Customers
Trezor reveals that the names, phone numbers and addresses of 67,000 additional US customers were exposed at ShipMonk. Private keys remain safe.

The data breach affecting Trezor customers is far larger than initially announced. The hardware wallet maker has revealed that 67,000 additional US customers had their personal information exposed at its logistics provider, ShipMonk. Names, email addresses, phone numbers, delivery addresses and order numbers are affected. Private keys were not compromised.
Crypto: 67,000 More Customers Affected
Trezor initially announced in August that 13,689 customers were affected. The discovery of 67,000 additional victims brings the total number involved in the incident to more than 80,000 people.
This new breach comes as vulnerabilities affecting hardware wallets have already reignited the debate over the security of self-custody.
The newly identified data concerns US customers who ordered Trezor products between November 2019 and August 2021.
This is where the incident becomes particularly embarrassing.
Trezor says it repeatedly asked ShipMonk to delete this old information and received written confirmations that this had been done. Its policy normally requires logistics partners to delete or anonymize order data after 90 days.
In its official update, Trezor now acknowledges that the data was still present in ShipMonk’s systems.
Bitcoin Remains Safe
The hardware wallet itself was not hacked.
Trezor’s systems, devices, private keys and recovery phrases were not exposed. A hacker therefore cannot use this database directly to move a user’s bitcoin.
The risk lies elsewhere: social engineering.
With a name, address, phone number and even the number of a genuine Trezor order, a scammer can craft a particularly convincing message. A fake security email, phone call, letter or technical support request may be all it takes for the victim to make a mistake.
This scenario echoes the malware and phishing campaigns already targeting wallets and exchange accounts.
Trezor reiterates a simple rule: no one working for the company will ask for a wallet’s recovery phrase. It should never be entered on a website received by email or shared with someone claiming to be support staff.
The Physical Address Is the Real Problem
An exposed email address is inconvenient. A physical address linked to the purchase of a hardware wallet is far more sensitive.
It may indicate that someone potentially owns cryptocurrency and directly reveal their place of residence. Trezor has also acknowledged a possible physical security risk for the affected customers.
The company is now preparing a system called “Anonymous Delivery.” It is expected to offer options including locker pickup, neutral packaging, a generic sender and the automatic deletion of delivery identifiers after receipt. The launch is planned for Europe in September and for the United States by the end of 2026.
Above all, the incident is a reminder that self-custody depends on more than a wallet’s cryptographic strength. Phishing campaigns are becoming sophisticated enough to exploit legitimate services and personal data.
Trezor customers’ bitcoin was not stolen. Their anonymity, however, has taken a serious hit.


