For the first time since its inception in 2013, Trezor, a crypto hardware wallet company backed by Czech Republic-based SatoshiLabs, has reported a major data breach impacting approximately 80,000 users.
Trezor announced, in a follow-up update on September 4, 2026, that an additional 67,000 customers in the United States, who ordered between November 2019 and August 2021, were affected by a compromised system at one of its shipping providers, ShipMonk.
“This leaked data affects another approximately 67,000 US customers and includes full exposure (name, email, phone number, shipping address, order number),” Trezor noted.
ShipMonk informed Trezor on September 2 that the initial data breach was larger than previously thought. On August 13, Trezor revealed that ShipMonk had notified them of their system breach on August 10 involving 13,689 customers.
As such, a total of 80,689 Trezor customers are at risk of highly targeted phishing scams, fraudulent phone calls or text messages, direct-mail scams, and potential physical security risks due to the exposure of their contact information and home addresses.
Meanwhile, Trezor has expressed disappointment with ShipMonk for ignoring the data retention policy, which mandated that all customer shipping details be deleted after 90 days despite written assurances that the data had been removed.
Consequently, Trezor highlighted that it is working on delivering its products anonymously to curb such incidents in the future.
“We take this matter very seriously and are working to ship anonymous delivery as soon as possible, so you can protect your personal information when placing an order,” the company confirmed.
Trezor joins crypto hardware wallets compromised in 2026
Multiple hardware wallet vendors have faced major security compromises this year, 2026. For instance, Ledger, a crypto hardware wallet, has reported multiple security incidents, including a supply-chain customer data breach via its payment processor Global-e as well as critical application software vulnerabilities in its Ethereum (ETH) and Zilliqa (ZIL) apps, as Finbold explained.
Recently, Coldcard, a Bitcoin (BTC) focused hardware wallet, experienced a far more devastating technical exploit when a long-standing firmware bug in its seed generator allowed attackers to drain over $116 million in Bitcoin.
Featured image via Shutterstock