Hardware wallet maker reveals 67,000 additional users were exposed after fulfillment partner ShipMonk retained outdated records.
Trezor, the hardware cryptocurrency wallet manufacturer, has revised upward its estimate of how many customers were affected by a recent data breach. The company now says approximately 80,700 US users had personal information exposed, according to reporting from Protos, AMBCrypto, Cryptopolitan and Finbold.
The expanded figure represents an increase of roughly 67,000 people beyond what Trezor initially disclosed. The company has attributed the larger scope of the breach to ShipMonk, a third-party fulfillment and mailing services provider it uses to ship products and communications to customers.
According to the reporting, ShipMonk retained older customer records that should have been purged or updated. Those outdated records were subsequently exposed, pulling additional users into the incident who were not part of Trezor's original breach notification.
Trezor has not disclosed the exact categories of personal information involved for the newly identified group of affected users, based on the available reporting. Data breaches involving hardware wallet companies carry particular weight in the cryptocurrency industry. These devices are marketed specifically as secure, offline storage for digital assets, and customers often expect the same rigor applied to their personal data as to their private keys.
The involvement of a third-party vendor highlights a recurring vulnerability in the crypto hardware supply chain. Even companies that build secure devices depend on external partners for shipping, mailing, and logistics. Those partners may not maintain the same security standards, creating exposure points outside a company's direct control.
Trezor has built its reputation on device-level security, using cold storage and offline signing to protect private keys. This incident, however, centers on customer data handled outside the device itself. That distinction matters for users assessing their actual risk, since exposed mailing or contact information differs materially from compromised wallet credentials or private keys.
The company's decision to revise the scope of the breach upward, rather than close the matter with its initial figure, suggests an ongoing internal review of ShipMonk's data handling practices. Further updates may follow as Trezor continues to audit records held by its vendors.
Data breaches at hardware wallet companies tend to generate reputational rather than direct financial market effects, since private keys and on-device security were not reported as compromised in this case. Still, expanded breach disclosures can erode customer trust in vendor-management practices across the hardware wallet sector more broadly.
Other companies that rely on third-party logistics or mailing providers may face increased scrutiny over how those partners store and retain customer data. Analysts and security researchers are likely to watch whether Trezor's response, including any compensation or security commitments to affected customers, sets a precedent for how the industry handles vendor-related breaches going forward.
Trezor's expanded breach disclosure underscores how third-party vendors can widen the scope of data incidents well beyond a company's initial estimates. Affected customers should watch for further updates as the review of ShipMonk's records continues.
Trezor said the increase stemmed from its fulfillment and mailing partner, ShipMonk, which had retained older customer records that were later exposed.
Trezor now estimates approximately 80,700 US customers were affected, an increase of about 67,000 over its original disclosure.
Based on available reporting, the breach involves customer data tied to mailing and fulfillment records, not device-level security or private keys.
No, ShipMonk is an independent third-party provider that Trezor uses for mailing and order fulfillment, according to the reporting.
We measure how many people read this site. That is all it is used for — there is no ad network, no advertising cookie, and nothing sold to anyone. Decline and the site works exactly the same. What we collect