Hardware wallet maker Trezor said on Friday that a data breach at its shipping provider, ShipMonk, is far larger than initially disclosed, with another 67,000 US customers now confirmed affected. The update came two days after ShipMonk passed on the finding, according to Trezor's post on X and a company blog entry.

What Was Exposed

The newly confirmed victims all placed orders between November 2019 and August 2021, making some of the exposed records close to seven years old. Exposed fields include names, email addresses, phone numbers, home addresses and order details.

Trezor says its own systems were not compromised and that devices, private keys and wallet backups are untouched. The concern is different: the data identifies confirmed hardware-wallet owners at specific front doors, a targeting map for phishing emails, calls and letters aimed at extracting seed phrases, as well as physical-security risks the company explicitly flagged to affected customers.

A Deletion Promise That Did Not Hold

When Trezor first disclosed the breach in August, it estimated about 14,000 users were affected — 13,689 precisely, per Decrypt's reporting — and attributed that limited scope to a 90-day data-deletion policy it had negotiated into its fulfillment partners' terms. The company says it repeatedly received written confirmation from ShipMonk that the older order data had been deleted. It evidently had not been. With Friday's update, the count stands at roughly 80,700 customers.

The intrusion traces back to a critical SQL injection flaw in the analytics tool Metabase, disclosed on August 6, which allowed unauthenticated attackers to steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk has reportedly received extortion emails attributed to the ShinyHunters group, though that attribution remains unconfirmed.

Why It Matters Beyond Trezor

The breach is a reminder that wallet security does not stop at the device. Impersonation-based scams that require no code exploit — phishing and social engineering — drove the majority of crypto losses in the first quarter of this year, roughly $306 million of $482 million lost, according to blockchain security firm Hacken.

Hardware-wallet owners are a favored target class. In February, owners of both Trezor and Ledger received forged letters printed with holograms and QR codes demanding activation of a fictitious security check. Stolen order data stays useful for years, because people rarely move or change phone numbers.

Trezor says it is working to roll out anonymous delivery — locker pickup, neutral packaging and generic sender details — so buyers no longer need to hand over a home address at all. The standard guidance bears repeating: a seed phrase is never typed into a website, read out on a call, or validated through any "security check."

TrustGrade tracks the security posture of exchanges, protocols and infrastructure providers. Verified, registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.