Trezor Data Breach Impact Now Reaches 81,000 Customers

Cryptocurrency hardware wallet maker Trezor has confirmed that the scope of a data breach tied to its shipping and logistics provider, ShipMonk, is far larger than originally reported. What began as a disclosure affecting roughly 14,000 customers in August has now grown to 81,000, after Trezor identified an additional 67,000 U.S. customers impacted by the same incident.

The breach did not originate inside Trezor's own systems. Instead, it stems from ShipMonk, the third-party company Trezor uses to handle order fulfillment and shipping. Because ShipMonk processes customer orders, it also holds personal details tied to those purchases, which is why a compromise at the logistics provider can expose Trezor customers even though Trezor's core security infrastructure was never touched.

From 14,000 to 81,000: How the Numbers Grew

Trezor first disclosed the breach on August 13, telling customers that attackers had accessed data belonging to nearly 14,000 people. That initial figure was already the third or fourth revision in a string of related updates, following earlier reports of a ShipMonk hack exposing 13,689 buyers and a separate disclosure putting the number at just over 13,000.

The latest update marks the largest jump yet. Trezor says an additional 67,000 U.S. customers were affected, bringing the confirmed total to 81,000. That is a nearly sixfold increase from the original estimate given when the breach was first disclosed. This pattern, where an initial breach disclosure is followed by repeated upward revisions, is common in incidents involving third-party vendors, since the company being breached is often the one investigating on its own systems while its partner conducts a separate, sometimes slower, review of exactly what was accessed.

As with the earlier phase of this breach, which exposed home addresses tied to nearly 14,000 customers, the data involved is tied to order fulfillment rather than Trezor's wallet software or private keys. That distinction matters: there is no indication that cryptocurrency holdings, wallet seeds, or device firmware were compromised. The exposure centers on personal information customers provided when placing orders, the kind of data a shipping company would need to deliver a package.

What This Means For You

If you have ever ordered a Trezor device, this expanded disclosure is worth taking seriously, even if you were not part of the original 14,000 customers notified in August. Because the newly identified 67,000 customers are specifically U.S.-based, anyone in the United States who has purchased a Trezor product should assume they could be included in this wider group until they receive direct confirmation either way.

The practical risk from this type of breach is not that someone can drain a cryptocurrency wallet remotely. Trezor's devices are built so that private keys never leave the hardware itself, and a shipping data breach does not change that. The real risk is more indirect: attackers who obtain names, shipping addresses, and order details tied to hardware wallet purchases now have a list of people who are known to own cryptocurrency and, often, their physical addresses. That combination is valuable to scammers running phishing campaigns, fake support requests, or in rarer cases, targeted physical crime aimed at crypto holders.

Because this breach has been updated multiple times since its initial disclosure, customers should not assume the current 81,000 figure is final. Companies investigating third-party vendor breaches frequently issue further updates as the vendor's own investigation continues.

Actionable Takeaways

If you have purchased a Trezor device, particularly within the past year, there are a few steps worth taking now. First, watch for official communication directly from Trezor confirming whether your account was among the affected group, and treat unsolicited emails or calls claiming to be from Trezor support with heightened suspicion, since breach data is often used to make phishing attempts look more convincing. Second, never share your wallet's recovery phrase or seed words with anyone, including someone claiming to represent Trezor support; legitimate support staff will never ask for this information. Third, if your home address was exposed, consider that this information linking you to cryptocurrency ownership is now potentially circulating, and stay alert for unusual mail, phone calls, or in-person contact referencing your purchase. Finally, keep an eye on future updates to this incident, since the repeated revisions so far suggest the final scope may still change.

Trezor's core wallet security remains unaffected by this breach, but the exposure of personal shipping data at this scale is a reminder that even privacy-focused hardware products depend on third-party vendors who may not meet the same security standard.