
Trezor data breach widens: 67,000 more buyers, orders as old as 2019
Trezor says another 67,000 customers were exposed in the ShipMonk breach, taking the total to roughly 80,700 from an initial 13,689. The number is not the worrying part. The new batch covers orders placed between November 2019 and August 2021, records up to seven years old, still sitting at a shipping contractor in 2026 after Trezor says it received written confirmation more than once that they had been deleted under contract.
The exposed fields are names, email addresses, phone numbers, home addresses and order numbers. Everyone in the new batch is in the United States.
Why a home address is the dangerous field
What did not leak matters too. Trezor's own systems were untouched, and so were the devices, the private keys and the wallet backups. The hardware did its job. The customer list is what failed.
An email address buys a phishing attempt. A home address paired with a purchase record is different, because it is confirmation that a specific person at a specific door owns crypto. Physical attacks on holders have been climbing all year:
- verified wrench attacks: 39 in the first half of 2025, 52 in the first half of 2026
- financial exposure from them: $10.5 million, then $124.1 million
- home invasions tied to crypto theft: 1 case, then 20, now the most common verified type
“Wallet backups should never be shared or typed into a website.”
— Trezor, Decrypt, 4 September 2026
Quote source: Decrypt, 4 September 2026
The precedent is six years old and still running. Ledger's 2020 e-commerce leak exposed about 272,000 records, and what followed was not only phishing. Customers received extortion letters demanding $700 to $1,000 in bitcoin, and some received replacement devices in the post, physically tampered with to capture the recovery phrase typed into them. That data still circulates in phishing campaigns today.
How the Trezor data breach happened
The hole itself was not exotic. ShipMonk ran Metabase, an analytics tool, and attackers used an unauthenticated SQL injection in its password reset endpoint, tracked as CVE-2026-72898 and rated 10.0 on the severity scale. It was exploited as a zero-day on 3 August and patched about a week later. ShipMonk then received extortion emails signed ShinyHunters.
What to do if you are on the list
For anyone on that list the practical guidance is short. No support desk, courier or manufacturer will ever ask for the recovery phrase, and a letter quoting your real order number proves nothing except that the leak is real. Our seed phrase entry explains why the phrase cannot be reset like a password, which is the reason attackers ask for it instead of trying to guess it.
The uncomfortable part is not fixable by the customer. Trezor asked for deletion, was told in writing it had happened, and the records were there anyway. Nothing a buyer does at checkout controls that.
Nothing here should be taken as financial advice; treat it as information to consider.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
279AI





