Trezor reveals 67,000 more users exposed in extended data breach

Trezor said an additional 67,000 US customers had their personal data leaked in a breach first reported in August.

04/09/2026 20:429 min read

Trezor, the maker of hardware cryptocurrency wallets, disclosed that a data breach it first reported in August is more extensive than initially thought.

On Friday, the Prague-based firm announced that another 67,000 customers in the United States had their names, email addresses, phone numbers, shipping addresses, and order numbers exposed. Trezor stated that the compromised data originated from orders placed from November 2019 through August 2021.

In August, Trezor initially reported that data from 11,742 customers across the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been compromised, including names, emails, phone numbers, and shipping addresses.

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.

Another 67,000 customers from the US who ordered between November 2019 and August 2021
 https://t.co/yDQvTlAA2S

— Trezor (@Trezor) September 4, 2026

Additionally, the breach exposed the names, cities, and email addresses of another 1,947 customers.

Trezor stated in Friday's announcement that its third-party logistics partner, ShipMonk, had provided false assurances that customer data had been deleted.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor wrote.

“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

Bitcoin Magazine did not receive an immediate response from either Trezor or ShipMonk.

In August, Trezor initially reported that the data leak occurred after ShipMonk suffered “unauthorized access to their systems containing customer data.”

Trezor also said it had emailed all affected customers directly. SatoshiLabs, Trezor's parent company, informed Bitcoin Magazine last month that it was looking into the matter.

Trezor is a widely used Bitcoin hardware wallet that also supports other cryptocurrencies.

Cybercriminals have previously targeted Bitcoin users' personal information. In 2020, an unauthorized actor breached Ledger's e-commerce and marketing database, exposing over 1 million email addresses and the contact details of nearly 10,000 customers.

Earlier this year, customers reported getting emails from Global-e, Ledger's payment processor, about a data breach in its cloud systems that leaked sensitive customer data.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles