If you bought a Trezor in 2019 and haven't thought about that purchase since, your name, your home address and your phone number are sitting in a file that someone else owns. The Trezor ShipMonk breach widened again on 4 September 2026, and the newest tranche of exposed records goes back much further than anyone expected. It covers United States orders placed between November 2019 and August 2021: data that the shipping vendor had told Trezor, in writing, was already gone.
What the September update added to the Trezor ShipMonk breach
Trezor first disclosed the incident on 13 August 2026, when the count stood at 13,689 customers and the exposure window ran from May to August of that year. In its updated statement, the company said it learned on 2 September that roughly 67,000 more United States customers were caught in the same breach, bringing the total to 80,689 people. Full records include names, phone numbers, email addresses and shipping addresses, while a smaller group of 1,947 had only a name, a city and an email exposed.
Nothing here touches a device. No private keys moved, no firmware was altered, and no wallet backup was in the leaked data, which is worth stating plainly because the word "breach" invites a much darker reading than the facts support. What leaked is the paperwork wrapped around the purchase, and paperwork turns out to have a longer half-life than most buyers assume.
The deletion that never happened
The mechanics are ordinary enough. ShipMonk, the fulfilment provider that packs and ships Trezor orders, ran a Metabase analytics instance, and attackers walked in through a zero-day SQL injection flaw tracked as CVE-2026-72898, rated the maximum 10.0 on the CVSS severity scale. Security researchers have attributed the intrusion to the ShinyHunters extortion group, which has spent the past year working through third-party platforms rather than the brands whose data sits inside them.
What makes this update different from August's is the age of the records. Trezor's own account is blunt about it: throughout the relationship, the company repeatedly asked ShipMonk to delete customer data and repeatedly received written confirmation that the deletion had happened. The 2019 to 2021 orders were still there. A contract said the data was gone, a vendor's assurances said the data was gone, and the breach proved otherwise, which is the uncomfortable part for every company that ships boxes to crypto owners. Ryder ships boxes too. So does every hardware wallet brand on the market, and none of us can hand a customer a receipt proving a subcontractor emptied a table.
Why a six-year-old order is worth more than a recent one
Think about what a 2019 order tells an attacker. It says this person bought a hardware wallet before the last bull run, which means they have probably been holding through it, and that they cared enough about custody to buy hardware rather than leaving coins on an exchange. Recency is not the useful signal here; tenure is. A shipping record from November 2019 is a filter for exactly the kind of holder a thief wants to find, and it comes with a street address attached.
That address is the part that changes the threat model. Data leaks in this industry normally produce a wave of phishing emails and scam calls, and this one will do that as well, but hardware wallet customer lists have a second use. TechCrunch reported that CertiK confirmed dozens of wrench attacks during 2025, a rise of 75 percent on the year before, with more than 40 million dollars taken in incidents where someone showed up in person and applied pressure until a seed phrase came out.
The part you can still control: your backup
You cannot un-leak an address, and you cannot audit a vendor's database from your kitchen table. What you can change is what an attacker gets if the worst version of this plays out and someone stands in your hallway asking questions. On most hardware wallets the answer is grim, because the entire wallet reduces to twelve or twenty-four words written on one card in one drawer, and a person under duress can recite them.
We built TapSafe Recovery so that no single object, and no single conversation, hands over the wallet. Recovery splits across an NFC Recovery Tag holding half and an encrypted share on your paired phone holding the other half, using a custom implementation of Shamir's Secret Sharing. Optional Recovery Contacts each hold a quarter, and none of them can see anything about your wallet. Your seed phrase stays available on the device as a last resort and follows the BIP-39 standard, so you are never locked to our hardware; it stops being the one thing standing between a stranger and your coins.
Paper backups are weak against water and time, and a steel plate fixes that much while leaving the deeper problem untouched, since your security still rests on one object surviving everything and staying secret forever. Splitting the crypto backup across separate components removes the single point of failure instead of hardening it.
What to do this week
Trezor's advice is sound and short: treat any message that pushes you to act immediately as hostile, and never type a wallet backup into a website or read it to anyone, including someone claiming to be support. Beyond that, assume the calls are coming. Attackers who bought this list will know your name, your city and which brand you own, which makes their opening line sound like a callback you were expecting.
Two practical moves are worth the twenty minutes. Add a passphrase or a PIN you have not used elsewhere, and check whether your delivery address is still where you keep your coins, because plenty of people have moved since 2019 and the leaked record points at an old house. If your setup depends on one card in one place, this is a reasonable week to change that.
Ryder One starts at 149 USD for the Starter Combo, with the Super Safe Combo at 179 USD, and both ship with the Recovery Tag, wireless charger and pouch. If you would rather your recovery not live or die by a single sheet of paper, take a look at Ryder One.
Meta description: Trezor's ShipMonk breach now covers 80,689 people, including 2019 orders a vendor said it deleted. What leaked, why old records matter, and what to do.




Share: