Morning Edition · Sunday, September 6, 2026Published at 2:01 AM EDT · New York
The newly identified records cover orders placed between November 2019 and August 2021, taking the publicly disclosed total to roughly 80,689 people who bought hardware wallets.

Trezor, the Czech hardware-wallet maker, said its logistics provider ShipMonk informed it on 2 September that an earlier intrusion exposed the data of about 67,000 additional United States customers. That is on top of roughly 13,700 customers notified in Trezor's first disclosure on 13 August, which implies about 80,689 affected people in total, although neither company has published a combined figure or checked for overlapping rows.
The exposed records include names, email addresses, phone numbers, shipping addresses and order numbers for purchases made between November 2019 and August 2021. Trezor says ShipMonk had given written assurances that older customer data was deleted under its contract and retention policy. The historical order records were still in ShipMonk's systems when attackers reached them. The intrusion itself came through zero-day exploitation of a critical structured-query-language injection flaw in Metabase, an analytics tool, tracked as CVE-2026-72898.
Trezor states that its own infrastructure and devices were not compromised, and that no wallet backups, private keys or device data were exposed. That distinction is real but narrow. The value of this data set to an attacker is not cryptographic. It is a list of home addresses belonging to people who bought a device whose entire purpose is holding bearer assets, which supports both targeted phishing and physical coercion.
The episode reveals a structural weakness in self-custody as it is actually sold. The security model of a hardware wallet protects the key. It does nothing about the retail supply chain that ships the device, and that chain runs through third-party logistics firms whose data-deletion promises are contractual rather than technical.
Custodial exchanges and issuers of exchange-traded crypto products, whose counterparty risk is disclosed and insured, gain against hardware-wallet vendors, and Trezor gains by placing the failure entirely with a logistics contractor.
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
Start a discussion in Townsquare.
More from this edition
The 67,000 figure and the Metabase zero-day, CVE-2026-72898, rated 10.0 are independently corroborated, but the roughly 80,689 total is a media addition of two disclosures with no overlap check, ShipMonk has not publicly confirmed Trezor's account of written deletion assurances, and the attribution to the ShinyHunters extortion group comes from a single security firm rather than from either company.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Buyers of self-custody hardware are exposed through their vendors' outsourced logistics, not through their keys, and the damage compounds because address lists do not expire. Every incident of this kind pushes some risk-averse holders toward custodians and exchange-traded products, where the counterparty risk is disclosed and insured rather than personal and physical. The commercial cost is borne by hardware vendors, who now must prove deletion rather than simply promise it.
What to watch
Observations to monitor, not financial advice.
Synthesized from: CryptoSlate · Bitcoin Magazine · The Hacker News
Comments
0No comments yet.