Illustration for: Trezor Breach Grows by 67,000 More US Customers

Trezor Breach Grows by 67,000 More US Customers

Trezor said shipping partner ShipMonk's data exposure is far larger than first disclosed, now covering roughly 80,000 customers after a SQL-injection flaw in ShipMonk's analytics platform went unpatched for weeks.

By the Numbers

~67,000
New customers exposed
~80,000
Total affected
SQL injection
Root cause
Aug. 13, 2026
Initial disclosure
Nov. 2019-Aug. 2021
Order window
TC
By the Markets Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

The breach traces to ShipMonk repeatedly telling Trezor it had deleted old customer records, per contractual obligation, when it apparently had not -- a vendor-assurance failure any company relying on third-party fulfillment should worry about.

2

No private keys, seed phrases, or wallet contents were exposed -- but names, emails, phone numbers, and shipping addresses for crypto hardware-wallet buyers are a phishing target list, not just a privacy footnote.

3

It's the second disclosure expansion in three weeks, a pattern suggesting Trezor itself lacked full visibility into ShipMonk's exposure until pressed.

TC

The VC Read · Trace's Take

Trace Cohen

This is a portfolio-company lesson dressed up as a crypto story: Trezor did everything right on its own stack and still got burned because a fulfillment vendor's data-retention promises weren't verified, just assumed. Any founder relying on a third-party logistics or KYC vendor should ask right now whether that vendor's deletion policy has ever been audited, not just contracted for -- 'we were told it was deleted' is not a defense regulators or plaintiffs' attorneys accept.

Analysis

Trezor disclosed Thursday that a data breach at its shipping and fulfillment partner ShipMonk is far larger than first reported, now exposing roughly 67,000 additional US customers on top of the 13,689 disclosed in August -- pushing the total to about 80,000 people, according to The Block and Trezor's own incident notice. The newly identified records belong to customers who ordered Trezor hardware wallets between November 2019 and August 2021, and include names, emails, phone numbers, shipping addresses, and order numbers.

ShipMonk first reported unauthorized access on August 10, tracing the intrusion to a SQL-injection vulnerability in its Metabase analytics platform. Trezor disclosed the initial, smaller breach on August 13. On September 2, ShipMonk told Trezor the exposure was substantially larger than originally scoped -- the second time in three weeks the numbers have grown, raising questions about how thoroughly ShipMonk audited its own systems before the first disclosure.

ShipMonk first reported unauthorized access on August 10, tracing the intrusion to a SQL-injection vulnerability in its Metabase analytics platform.

A vendor-assurance failure, not a wallet compromise

Trezor, part of Prague-based SatoshiLabs since it shipped the first commercial hardware wallet in 2013, has been explicit that no private keys, seed phrases, or wallet contents were touched -- the exposure sits entirely in ShipMonk's order-fulfillment database, not Trezor's own security stack. That distinction matters for a company whose value proposition, like rival Ledger's, rests on keeping crypto credentials offline and out of reach of exactly this kind of third-party breach. Ledger and Trezor together control more than 70% of the global hardware-wallet market, and both have suffered fulfillment-related data exposures before -- Ledger's 2020 e-commerce breach leaked over a million customer records and led to years of targeted phishing against known wallet owners.

The detail most damaging to ShipMonk specifically: Trezor said the fulfillment provider had repeatedly given written assurances that older customer records had been deleted per contractual data-retention requirements, but the historical order data remained in ShipMonk's systems regardless. For any company outsourcing fulfillment, KYC, or customer data handling, that's the operative risk here -- a signed data-retention clause is only as good as the vendor's actual deletion practices, which are rarely independently audited. Owners of a hardware wallet whose entire pitch is eliminating trust in third parties are now the ones most exposed by trusting one.

ShareXLinkedInEmail

Key Sources

3 sources
SourceTrezor
SupportThe Block

Reported by The Block · First reported by Trezor · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.