# Trezor Says a Shipping Partner Exposed 67,000 More Customer Records It Was Told Had Been Deleted

The newly identified records cover orders placed between November 2019 and August 2021, taking the publicly disclosed total to roughly 80,689 people who bought hardware wallets.

- Published: 2026-09-06T06:01:25.324Z
- Canonical: https://polylog.news/crypto/2026-09-06/trezor-says-a-shipping-partner-exposed-67-000-more-customer
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CryptoSlate](https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/), [Bitcoin Magazine](https://bitcoinmagazine.com/news/trezor-data-breach-worse-than-reported), [The Hacker News](https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html)

Trezor, the Czech hardware-wallet maker, said its logistics provider ShipMonk informed it on 2 September that an earlier intrusion exposed the data of about 67,000 additional United States customers. That is on top of roughly 13,700 customers notified in Trezor's first disclosure on 13 August, which [implies about 80,689 affected people in total](https://cryptoslate.com/users-exposed-by-trezor-breach-grows-sixfold-after-supposedly-deleted-shipping-logs-are-found/), although neither company has published a combined figure or checked for overlapping rows.

The exposed records include names, email addresses, phone numbers, shipping addresses and order numbers for purchases made between November 2019 and August 2021. Trezor says [ShipMonk had given written assurances](https://bitcoinmagazine.com/news/trezor-data-breach-worse-than-reported) that older customer data was deleted under its contract and retention policy. The historical order records were still in ShipMonk's systems when attackers reached them. The intrusion itself came through [zero-day exploitation of a critical structured-query-language injection flaw in Metabase](https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html), an analytics tool, tracked as CVE-2026-72898.

Trezor states that its own infrastructure and devices were not compromised, and that no wallet backups, private keys or device data were exposed. That distinction is real but narrow. The value of this data set to an attacker is not cryptographic. It is a list of home addresses belonging to people who bought a device whose entire purpose is holding bearer assets, which supports both targeted phishing and physical coercion.

The episode reveals a structural weakness in self-custody as it is actually sold. The security model of a hardware wallet protects the key. It does nothing about the retail supply chain that ships the device, and that chain runs through third-party logistics firms whose data-deletion promises are contractual rather than technical.

## What this means

Buyers of self-custody hardware are exposed through their vendors' outsourced logistics, not through their keys, and the damage compounds because address lists do not expire. Every incident of this kind pushes some risk-averse holders toward custodians and exchange-traded products, where the counterparty risk is disclosed and insured rather than personal and physical. The commercial cost is borne by hardware vendors, who now must prove deletion rather than simply promise it.

## What to watch

- Whether Trezor or ShipMonk publishes a reconciled total and an overlap check, since the absence of one figure is the main reason the true count is still unclear.
- Reports of targeted phishing or home robberies traced to the exposed list, which would convert a data breach into direct financial loss.
- Whether hardware-wallet vendors move to pseudonymous ordering or in-region fulfilment they control, the only changes that would remove the exposure rather than manage it.
