Hardware wallet maker Trezor has disclosed that a shipping partner exposed personal data belonging to another 67,000 customers in the United States, on top of a smaller breach the company had already reported weeks earlier. The company says the partner, a fulfillment provider called ShipMonk, had repeatedly assured Trezor that old order data had been deleted, only for that data to resurface after attackers broke in. For an industry built around securing private keys, the incident is a reminder that the weakest link in supply chains is often not the product itself but the vendors handling it afterward.
Trezor makes hardware devices that store cryptocurrency offline, a category of product whose entire appeal rests on keeping sensitive material away from internet-connected systems. The breach at ShipMonk did not touch the wallets or the cryptographic material they protect, but it did expose the kind of personal information that criminals can use to target owners directly, rather than trying to break the devices themselves.
What ShipMonk Exposed This Time
The newly disclosed exposure covers customer names, email addresses, phone numbers, shipping addresses, and order numbers tied to purchases made between November 2019 and August 2021. Trezor said the exposure affects roughly 67,000 additional United States customers, on top of the 13,689 it had already disclosed the previous month as either fully or partially exposed. Combined, the two disclosures put the total number of affected customers at close to 81,000. A subset of 1,947 customers had a narrower exposure limited to names, cities, and email addresses, without shipping addresses attached.
A Breach That Was Not Supposed to Be Possible
What frustrated Trezor most was that the exposed data was meant to be gone. The company’s stated retention policy deletes or anonymizes customer data 90 days after a purchase is complete, a window chosen to cover the full life of an order, including delivery, returns, and any refunds or replacements. Trezor said it had received written confirmation from ShipMonk over the course of their relationship that this deletion had, in fact, occurred, in line with their contract and data-handling policy. The persistence of years-old order records well past that window suggests the confirmations Trezor received did not reflect what was actually happening inside ShipMonk’s systems.
How the Attackers Got In
ShipMonk told Trezor about unauthorized access to its systems on August 10, 2026, and the intrusion has since been traced to exploitation of a critical SQL injection flaw in Metabase, a data-visualization tool, tracked as CVE-2026-72898 and rated at the maximum severity score of 10.0. According to reporting from The Hacker News, the extortion group ShinyHunters has been linked to the intrusion, which enterprise blockchain security firm Halborn described as a software supply chain attack that began with a zero-day vulnerability in third-party software rather than any flaw in Trezor’s own infrastructure. Halborn said the case illustrates why organizations need full visibility into the risk posed by vendors who hold their customers’ data, since Trezor’s own security posture had little bearing on what happened inside ShipMonk’s Metabase instance.
The Risk Facing Affected Customers
Trezor has said it is notifying affected customers directly and has warned them to watch for social engineering attempts that use the leaked details to appear credible. Because the exposed information ties real names to home addresses and confirms that the recipient owns cryptocurrency hardware, the company flagged the data as useful for scam emails, fraudulent phone calls, and letters impersonating Trezor itself, as well as a potential physical security risk for people whose addresses are now linked to known crypto holdings. ShipMonk has not issued a public acknowledgment of the incident, though it is reported to have secured the affected systems and strengthened its security following the breach.
Why Hardware Wallet Makers Keep Losing This Fight Downstream
Trezor’s core product exists specifically to keep private keys away from any internet-connected system, and nothing about this breach touched that cryptographic layer. The exposure instead ran through the ordinary logistics chain that gets a physical device from a warehouse to a customer’s door, a part of the business that necessarily involves handing real names and shipping addresses to an outside vendor. That structural reality is what makes supply-chain incidents like this one difficult to prevent through the manufacturer’s own security work alone, since the company’s defenses are only as strong as the retention promises made by every partner who touches customer data afterward.
The scale of the miscount also stands out. Trezor said it had received written assurances that ShipMonk had deleted the relevant data in line with their contract, yet records dating back to November 2019 were still sitting in ShipMonk’s systems when attackers broke in nearly two years after Trezor’s own 90-day retention window should have erased them. That gap between a documented deletion policy and what was actually stored is the detail security researchers are likely to scrutinize most closely as the case develops, since it raises the question of how many other vendors are holding onto customer data they have already certified as gone.
This article was created with the assistance of AI and reviewed by an editor.
More from Morning Overview