I think the most concerning part of this Trezor breach isn't just the number of customers affected, but the fact that old customer records reportedly remained with a logistics provider years after they were supposed to be deleted. For hardware-wallet users, this shows that protecting crypto isn't only about securing private keys — the personal information connected to a purchase can also create serious risks.
Hardware wallet manufacturer Trezor has expanded the number of customers affected by a data breach at its logistics partner ShipMonk, saying an additional 67,000 U.S. customers may have had their information exposed.
Trezor initially reported that 13,689 customers were affected. The newly disclosed group would bring the total to roughly 80,689 people, although the company has not published a single combined figure or provided enough underlying data to determine whether there is any overlap between the two groups.
The newly identified records reportedly relate to U.S. orders placed between November 2019 and August 2021. They included names, email addresses, phone numbers, shipping addresses and order numbers.
That combination of information is particularly sensitive for hardware-wallet customers because it can potentially connect a person's identity and physical address with the fact that they purchased a crypto-security device.
Old records remained despite deletion assurances
Trezor's initial disclosure on Aug. 13 identified 11,742 customers with full exposure and another 1,947 with partial exposure. At the time, the company said older order information had already been deleted, although a later clarification acknowledged that some older orders were present among partially exposed records.
The company's latest update paints a different picture.
Trezor said it had repeatedly requested confirmation from ShipMonk that the relevant information had been deleted and received written assurances that the data was gone. However, records dating back to 2019 were apparently still present in the vendor's systems.
Trezor's delivery-data policy states that customer information should normally be removed from both Trezor's systems and those of its fulfillment partners after 90 days, except when information is required to resolve ongoing order-related issues.
The company has not publicly released the deletion assurances or the dates on which they were provided.
According to reporting from BleepingComputer, a ShipMonk notification linked the original unauthorized access to a vulnerability involving the Metabase analytics platform. Metabase previously said an August zero-day vulnerability could potentially allow an attacker to obtain an administrator session and download large amounts of database information.
As the logistics-provider incident was investigated further, the discovery of historical records significantly increased the number of Trezor customers believed to have been exposed.
Trezor wallets themselves were not compromised
There is an important distinction here: the breach did not compromise Trezor's wallet systems.
The company said its own systems, products and services were not breached and that its hardware devices remained secure. The information identified in the incident involved customer and order details rather than wallet recovery seeds, private keys or cryptocurrency balances.
The bigger concern is what attackers could potentially do with the information surrounding the wallet purchase.
Trezor warned that exposed details could be used to create convincing phishing emails, fraudulent phone calls or letters, and potentially even attempts at physical targeting.
However, the company has not reported a confirmed downstream attack resulting from this newly identified dataset, meaning these are potential risks rather than documented consequences.
Trezor said it contacted every newly affected customer directly and emphasized that customers should never share their wallet backup or enter recovery information into a website.
For me, the biggest lesson is that hardware-wallet security doesn't end with the device itself. Your private keys may remain protected, but the personal information created when you purchase and receive a wallet can still become a security risk.
A company can have a strict 90-day deletion policy on paper, but if a third-party vendor keeps the information for years, that policy provides little real protection. This incident is a reminder that crypto security also depends on how exchanges, manufacturers and logistics companies handle the data surrounding the assets.

