Trezor’s data breach got about six times bigger on Sept. 4, and the reason is one of the least glamorous failures in security: a vendor said it deleted the files, and it hadn’t.
The hardware wallet maker now says the incident at logistics provider ShipMonk exposed contact and order data for another roughly 67,000 U.S. customers. Add that to the 13,689 people Trezor originally named and you get about 80,689. Trezor hasn’t published that combined number itself, and it hasn’t released row-level data showing whether the two groups overlap. Its wording is the tell: the word “another” means the company treats these records as additional to the first batch, not a recount of it.
The records that were supposed to be gone
The newly disclosed data covers U.S. orders placed from November 2019 through August 2021. Names, email addresses, phone numbers, shipping addresses, order numbers.
Trezor’s own delivery-data policy says customer details should be deleted from both its systems and its fulfillment partner’s after 90 days, with exceptions for unresolved order issues. Records from 2019 sat in a vendor’s systems until 2026. That’s not a 90-day window with a rounding error.
Trezor said it repeatedly asked ShipMonk to confirm deletion and repeatedly received written assurances that the data was gone. The assurance letters haven’t been made public, and neither have their dates. So there’s no way for a customer to check when Trezor asked, what it was told or how far the paperwork drifted from what was actually sitting on the server.
The first count was wrong twice
When Trezor disclosed the breach on Aug. 13, the numbers were smaller and more precise: 11,742 customers with full exposure, 1,947 with partial exposure. That first account also said older order data had already been deleted.
An Aug. 14 clarification walked part of that back, acknowledging that some of the partially exposed records did include older orders. The Sept. 4 update reverses the rest of it.
Three disclosures, three different pictures of the same dataset. That’s what happens when your understanding of an incident depends on a third party’s description of its own housekeeping.

How the data walked out
A ShipMonk notification attributed the original unauthorized access to a vulnerability in the analytics platform Metabase. Metabase said the August zero-day could create a session tied to an administrator account and allow bulk table downloads.
An admin session plus bulk export is about as clean a path to a full customer table as an attacker gets. Once the provider incident was reassessed, the retained historical data expanded the number of Trezor customers known to be exposed.
Your keys are fine. Your address isn’t.
Trezor said its systems, products and services were not compromised, and that its devices remained secure. The exposed fields are contact and order data. No recovery seeds, no private keys, no wallet funds.
That distinction matters technically and it matters much less practically. A leaked marketing list tells an attacker you exist. This one connects an identifiable person to a physical address and to the fact that they bought a hardware wallet, which is a reasonable proxy for holding crypto worth protecting.
Trezor warned the information could support convincing scam emails, fraudulent calls or letters, and potential physical targeting. Worth being precise about the certainty here: the Sept. 4 update didn’t identify a confirmed downstream attack traced to this dataset. These are risks, not documented consequences. Nobody should be reading the update as evidence that anyone has been robbed.

What to do if you ordered between 2019 and 2021
Trezor said it emailed every newly affected customer directly, and that anyone who didn’t receive its incident notice wasn’t affected. Check the address you used at checkout, including whatever inbox you’d forgotten you used five years ago.
The company’s advice is the same advice that has always been true and is now urgent for a specific 67,000 people: never share a wallet backup, and never type one into a website. No legitimate support process will ever ask.
The uncomfortable lesson isn’t about cryptography. Trezor’s threat model held. The keys stayed on the device, the seed never left the customer’s hands, and the attacker got nothing that unlocks funds. What failed was the mundane paper trail every physical product creates on its way to a doorstep, held by a company Trezor doesn’t run, governed by a deletion policy nobody verified. If you sell a device whose entire value proposition is that you don’t have to trust anyone, the shipping label is where that promise ends.


