Mark RadarMARK RADAR
About
EN
Sign in

Trezor Says ShipMonk Breach Exposed 67,000 More U.S. Customers

4 reports · First detected 2026-09-04 · Last active 2026-09-04

Hardware wallets are designed to keep cryptocurrency private keys offline, but customer information generated during a purchase can remain with outside logistics providers. The exposure of names, phone numbers and home addresses is especially sensitive for crypto owners because the records can support targeted phishing, impersonation or physical-security threats. The incident highlights how a wallet maker’s security perimeter extends beyond its devices and software to vendors handling fulfillment and historical order data.

Trezor said the scope of a breach involving logistics provider ShipMonk has widened, affecting an additional 67,000 customers in the United States. The compromised records cover orders placed from 2019 through 2021 and include customers’ names, telephone numbers and addresses. Trezor said it had received repeated assurances that the information had been deleted and expressed disappointment that ShipMonk failed to carry out the required data-removal procedures.

All Coverage

4 original reports

The Backstory

The history behind this event
Trezor Shipping Partner Breach Exposes Data of Nearly 14,000 Customers2026-08-18 · 10 reports · similarity 0.97

Trezor, a maker of hardware wallets designed to keep cryptocurrency private keys offline, still relies on outside providers to process orders and deliveries. That creates a separate supply-chain risk: leaked customer details can help criminals identify crypto holders and craft convincing phishing messages, impersonation attempts or even physical threats. The incident underscores that cold-storage security does not eliminate exposure created by commerce and logistics systems.

Trezor said in August that a breach at fulfillment and logistics partner ShipMonk exposed personal information belonging to nearly 14,000 customers, including some shipping addresses. Reports linked the intrusion to a possible Metabase vulnerability, though the compromise occurred in the provider’s environment. Trezor notified affected customers and said its hardware wallets, users’ private keys and cryptocurrency funds were not compromised in the incident.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)