Trezor said Friday that another 67,000 U.S. customers were caught in a data breach at shipping provider ShipMonk, expanding the scope of an incident the company disclosed last month.
The exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, home addresses, email addresses and order numbers. The total number of affected customers has grown from approximately 13,700 to roughly 80,700.
Trezor stated that it repeatedly requested and received written confirmation from ShipMonk that customer records had been deleted in accordance with its contract and data policy. The company expressed disappointment upon learning the data had not been deleted.
Security Implications
Trezor's own systems were not breached, and customer devices, private keys and wallet backups remain untouched. However, the exposed records identify confirmed hardware wallet owners at specific addresses, creating physical security risks.
The company warned affected customers about threats including fraudulent emails, calls and letters. Trezor emphasized that wallet backups should never be shared or entered into websites.
Owners of hardware wallets have previously been targeted with forged letters bearing holograms, QR codes and forged signatures attempting to trick them into activating fake security checks.
Breach Origins
The intrusion stems from a critical SQL injection flaw in the analytics tool Metabase, disclosed on August 6, which allowed unauthenticated attackers to steal credentials for connected databases. Other companies including laptop maker Framework and form builder Tally were affected by the same vulnerability.
ShipMonk reportedly received extortion emails attributed to ShinyHunters, though that attribution remains unconfirmed.
Response Measures
Trezor said it is working to offer anonymous delivery options using locker pickup, neutral packaging and generic sender details so customers need not provide home addresses.


