TREZOR LEAK GROWS BY 67,000 BUYERS — HOME ADDRESSES, FROM RECORDS A VENDOR SWORE IN WRITING WERE DELETED — THE KEYS HELD, THE PAPERWORK DIDN’T
A hardware wallet protects your coins from the internet. Nothing protects you from the customer database.
Trezor said this morning its shipping-vendor breach is much bigger than first reported: 67,000 more U.S. buyers, on top of 13,689 already disclosed — roughly 80,000 people. Names, emails, phone numbers, order numbers, and home addresses, from orders placed between November 2019 and August 2021. The devices did their job. No keys, no seed words, no firmware touched. The failure was upstream and it was procedural: the vendor, Shipmonk, confirmed in writing — more than once — that these records were deleted under a 90-day retention policy. They weren’t. Then an unknown flaw in the vendor’s analytics tool walked them out the door. This is the third time Trezor buyers have been exposed by someone else’s database — 106,000 in 2022, 66,000 in 2024 — and the company’s answer, locker pickup and auto-deleted shipping records, concedes the point the Technologist has made for years: the database was the defect. A list of names, home addresses, and confirmed hardware-wallet ownership is not a phishing risk. It is a target list. The rule stands: no one from any wallet company will ever ask for your seed words. No one.
KEY RECEIPTS
Trezor alert, Sept 4: 67,000 additional U.S. customers exposed via the Shipmonk breach; U.S. orders Nov 2019–Aug 2021 (Trezor on X, via Bitcoin.com).
Running total: ~80,000 people including the 13,689 disclosed earlier across several countries.
Exposed: names, emails, phone numbers, shipping addresses, order numbers. NOT exposed: private keys, seed phrases, devices, wallet backups.
The procedural failure: Trezor says Shipmonk confirmed deletion in writing, consistent with contract and a 90-day retention policy. The records were 5–7 years old.
Root cause: a previously unknown SQL-injection flaw in Metabase, an analytics tool used by Shipmonk; patched around Aug 6.
Pattern: ~106,856 Trezor customers exposed in 2022 (Mailchimp), ~66,000 in 2024 (support portal). Devices uncompromised each time.
The fix being rolled out: Anonymous Delivery — locker pickup, neutral packaging, shipping identifiers auto-deleted. Europe this month, U.S. by end of 2026.
Physical risk is the tail: Trezor itself warns leaked addresses could put customers at physical risk. France logged 77 crypto kidnapping cases this cycle.
Related: What KYC databases cost when they leak.
Running total: ~80,000 people including the 13,689 disclosed earlier across several countries.
Exposed: names, emails, phone numbers, shipping addresses, order numbers. NOT exposed: private keys, seed phrases, devices, wallet backups.
The procedural failure: Trezor says Shipmonk confirmed deletion in writing, consistent with contract and a 90-day retention policy. The records were 5–7 years old.
Root cause: a previously unknown SQL-injection flaw in Metabase, an analytics tool used by Shipmonk; patched around Aug 6.
Pattern: ~106,856 Trezor customers exposed in 2022 (Mailchimp), ~66,000 in 2024 (support portal). Devices uncompromised each time.
The fix being rolled out: Anonymous Delivery — locker pickup, neutral packaging, shipping identifiers auto-deleted. Europe this month, U.S. by end of 2026.
Physical risk is the tail: Trezor itself warns leaked addresses could put customers at physical risk. France logged 77 crypto kidnapping cases this cycle.
Related: What KYC databases cost when they leak.
The wallet held. The database leaked.
Tick tock. Next block.
Tick tock. Next block.
Trezor security alert (X) + Bitcoin.com · Fri Sep 4 2026 · 8:30 AM ET