Hardware wallet manufacturer Trezor announced that roughly 67,000 additional U.S. buyers were impacted by a security incident at fulfillment partner ShipMonk, following its initial report that nearly 14,000 customers suffered personal data exposure.
Trezor stated on Friday that ShipMonk communicated on September 2 that the security breach spanned a wider scope than previously stated, incorporating purchase details from individuals who bought items between November 2019 and August 2021. These newly uncovered files include customer full names, electronic mail addresses, telephone numbers, postal destinations, and transaction identifiers.
The business explained that it had repeatedly requested ShipMonk to erase the records throughout the course of their partnership and obtained written guarantees that the information had been purged in accordance with their agreement, privacy guidelines, and prior exchanges. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor noted.
Trezor systems not compromised
Trezor clarified that its internal networks remained untouched and its hardware wallets continue to stay safe. The firm stated it has dispatched electronic mail notifications to all consumers impacted by this latest revelation. It cautioned users to be vigilant against phishing messages, fraudulent telephone calls, and postal mail, alongside potential physical safety hazards.
When Trezor initially revealed the security lapse on August 13, it reported that 11,742 buyers experienced exposure of their full names, electronic mail addresses, telephone numbers, and shipping locations, while another 1,947 had their full names, municipalities, and electronic mail addresses leaked. Trezor pointed out at the time that the incident was mitigated by a rule mandating fulfillment vendors to erase or anonymize purchase data 90 days following delivery.
Physical wallet buyers whose residential addresses get leaked can encounter dangers beyond digital fraud. A 2020 Ledger breach leaked details belonging to upwards of 270,000 users, where full names, electronic mail addresses, telephone numbers and, in certain instances, home locations were subsequently shared on a hacker forum. Ledger users have persistently shared experiences of getting deceptive phone calls and physical letters years later.
Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.
© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Originally published at https://www.theblock.co/news/business/2026-09-04-trezor-says-shipmonk-breach-affected-another-67000-customers-413540.