← All Crypto briefings

Crypto

Trezor says shipping partner exposed 67K more customers

2026-09-06

Trezor thought old customer data was long gone. It was wrong. On Sept. 4, the hardware-wallet maker said its shipping partner, ShipMonk, never actually deleted years-old order records. It was supposed to. A breach at ShipMonk, first disclosed last month, turns out to be much bigger. Roughly 67,000 more US customers had their information exposed.

The data itself isn't the scary kind. No wallet passwords, seed phrases, or device security were touched — Trezor says the hardware wallets themselves stay safe. What leaked instead was names, emails, phone numbers, and shipping addresses, from orders placed between 2019 and 2021. That's still enough for scammers to run convincing phishing attacks against crypto holders, who are frequent targets. Trezor has a policy requiring partners to delete data after 90 days specifically to prevent this. This time, the policy didn't work, because ShipMonk didn't follow it.

Keep reading — what to watch

Will this change how crypto companies vet their vendors? Trezor's own security wasn't the problem here — a sloppy shipping partner was. That's a warning for every crypto company that outsources parts of its business to outside vendors. A wallet can be perfectly secure and still put its customers at risk. That happens if the company handling its shipping labels isn't as careful.

This story is written by AI from the sources above, checked against them before publishing. If something here still reads wrong, tell us and we'll correct it.

← AI Biotech →