Trezor Data Breach Expands: 67,000 More U.S. Customers Exposed

Stylized hardware wallet surrounded by translucent blocks and hex grid with flowing data ribbons in green and gold tones

Tally of Exposed Users Keeps Growing

The number of Trezor customers affected by a third-party data breach has surged once again, with an additional 67,000 U.S. users confirmed to have had their personal information exposed.

This latest disclosure brings the total number of affected Trezor customers to approximately 80,700, up from the earlier estimate of just under 14,000. The scale of the breach has grown substantially since August, when the company first acknowledged the issue and believed its impact was far more limited.

ShipMonk’s Lax Data Deletion Under Fire

A key factor behind the expanded breach is ShipMonk’s failure to delete old customer records, despite written assurances to Trezor that such data would be removed. As a result, information from orders dating back as far as late 2019 remained accessible and was ultimately compromised. ShipMonk notified Trezor about the additional affected users only two days before the public announcement, raising questions about transparency and responsiveness in handling customer data.


Orders placed between November 2019 and August 2021 were among those whose details—including names and addresses—were left vulnerable.

Trezor itself maintains that its internal systems were never breached; only external order data held by ShipMonk was exposed.

SQL Flaw Linked to Expanding Breach

The breach can be traced to a critical vulnerability in Metabase, an analytics tool used by ShipMonk. Specifically, an SQL injection flaw—publicly disclosed on August 6—allowed attackers to access sensitive customer information stored in ShipMonk’s systems. This technical loophole provided the entry point for unauthorized parties to obtain data on tens of thousands of Trezor customers who had interacted with the company over a nearly two-year span.

ShipMonk has reportedly received extortion emails linked to a group known as ShinyHunters; however, this attribution remains unconfirmed. The presence of such emails underscores the ongoing risk that breached data could be further weaponized or sold within cybercriminal circles.

Customers Face Fresh Phishing Threats

For affected users, the most immediate risk is phishing—fraudulent attempts to extract sensitive information or funds by impersonating legitimate companies or contacts. In January 2024 alone, Trezor reported that around 66,000 users who had contacted its support team since December 2021 were at heightened risk for such attacks. Blockchain security firm Hacken has quantified the broader threat: impersonation-based scams cost crypto users $306 million out of $482 million lost industry-wide in just the first quarter of this year.

While no private keys or wallet backups were compromised—the core security features of Trezor devices remain intact—the exposure of contact details makes it easier for attackers to craft convincing messages targeting individual users. This contrast between robust device security and vulnerable external data highlights a persistent tension in crypto: even if hardware stays secure, third-party partners can still create new risks for end-users.

Why it matters: Practical Impact and Next Steps

The expanding scope of this breach serves as a cautionary tale for crypto companies relying on third-party service providers. Despite assurances from ShipMonk regarding data deletion protocols, records from orders placed as early as November 2019 were left exposed—leaving thousands at risk years after their purchases. In response to mounting concerns over privacy and safety, Trezor is now working on offering anonymous delivery methods such as locker pickups and neutral packaging for future orders.

The headline number—over 80,000 affected customers—captures attention, but the context is messier: while device-level security has not been compromised according to decrypt.co, trust in how user information is handled remains shaken. For many crypto holders who value privacy above all else, these revelations may prompt a reevaluation not just of which wallet they use but also how and where they buy it.

What could move the market

If ShipMonk or Trezor confirm that the extortion emails reportedly received by ShipMonk are linked to ShinyHunters, immediate concerns about targeted phishing or impersonation attacks could increase, especially given that the breach now affects roughly 80,700 Trezor customers in the US whose personal data was exposed.