Analysis
Trezor disclosed Thursday that a data breach at its shipping and fulfillment partner ShipMonk is far larger than first reported, now exposing roughly 67,000 additional US customers on top of the 13,689 disclosed in August -- pushing the total to about 80,000 people, according to The Block and Trezor's own incident notice. The newly identified records belong to customers who ordered Trezor hardware wallets between November 2019 and August 2021, and include names, emails, phone numbers, shipping addresses, and order numbers.
ShipMonk first reported unauthorized access on August 10, tracing the intrusion to a SQL-injection vulnerability in its Metabase analytics platform. Trezor disclosed the initial, smaller breach on August 13. On September 2, ShipMonk told Trezor the exposure was substantially larger than originally scoped -- the second time in three weeks the numbers have grown, raising questions about how thoroughly ShipMonk audited its own systems before the first disclosure.
“ShipMonk first reported unauthorized access on August 10, tracing the intrusion to a SQL-injection vulnerability in its Metabase analytics platform.”
A vendor-assurance failure, not a wallet compromise
Trezor, part of Prague-based SatoshiLabs since it shipped the first commercial hardware wallet in 2013, has been explicit that no private keys, seed phrases, or wallet contents were touched -- the exposure sits entirely in ShipMonk's order-fulfillment database, not Trezor's own security stack. That distinction matters for a company whose value proposition, like rival Ledger's, rests on keeping crypto credentials offline and out of reach of exactly this kind of third-party breach. Ledger and Trezor together control more than 70% of the global hardware-wallet market, and both have suffered fulfillment-related data exposures before -- Ledger's 2020 e-commerce breach leaked over a million customer records and led to years of targeted phishing against known wallet owners.
The detail most damaging to ShipMonk specifically: Trezor said the fulfillment provider had repeatedly given written assurances that older customer records had been deleted per contractual data-retention requirements, but the historical order data remained in ShipMonk's systems regardless. For any company outsourcing fulfillment, KYC, or customer data handling, that's the operative risk here -- a signed data-retention clause is only as good as the vendor's actual deletion practices, which are rarely independently audited. Owners of a hardware wallet whose entire pitch is eliminating trust in third parties are now the ones most exposed by trusting one.