Trezor breach widens to 80,000 users after new disclosure

Trezor revealed another 67,000 US users were leaked in mailing partner breach, total over 80,000.

04/09/2026 13:438 min read

Trezor apologized in a post on X, stating it is “terribly sorry” after disclosing that an additional 67,000 US users were affected by the breach at its mailing partner last month. The incident now impacts more than 80,000 customers.

Last month, Trezor first disclosed that the personal data of 13,689 customers had been compromised following an intrusion into ShipMonk's systems.

Initially, Trezor minimized the breach's scope by asserting that a 90-day data policy enforced by its partners would delete old data and limit the leak.

Now, however, Trezor says that policy was never actually enforced and the data was not deleted.

Trezor asserted, “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.”

The company continued, “We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.”

Breaches of this type can allow criminals to target cryptocurrency users more effectively because they have additional details to customize their attacks.

Trezor says it did not foresee further data exposure

Trezor informed Protos that it is too soon to determine its response to ShipMonk and that it is arranging another audit of the mailing partner.

Trezor asserts that on August 10, ShipMonk notified it of the initial leak involving orders from the prior 90 days. On September 2, ShipMonk informed Trezor that the breach actually extended back to 2019 and 2021.

Trezor said, “Our understanding is that our cooperation from those years was overlooked when the original scope was established.”

Asked why ShipMonk was the one to disclose the additional breaches, Trezor stated it had “no reason to expect it” because of ShipMonk's repeated reassurances.

Last month Trezor contacted Protos first to share the leak details, but this time it did not initiate contact.

When questioned about this, Trezor responded, “The information is public and it is not behind anything. Our priority was reaching the people actually affected.”

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles