Trezor's 'Deleted' Shipping Logs Just Made A Bad Breach Brutally Worse
Trezor's breach numbers jumped from 13,689 to nearly 80,689 after shipping records that were 'deleted' resurfaced at vendor ShipMonk. That's six times the original impact and a brutal reminder that data doesn't die when you ask nicely.
I'll be honest. When Trezor first said a logistics breach exposed 13,689 customers, I shrugged. Small number. Contained blast radius. Move on.
Then Sept. 4 hit. And just like that, the real number is roughly six times bigger.
Trezor now says another 67,000 U.S. customers had contact and order data exposed at ShipMonk. That's the shipping vendor behind the original breach. The combined implied total? About 80,689 people. No public row-level overlap check, so maybe some names appear in both groups. Maybe not. But Trezor hasn't given us a clean combined total. That's a problem.
The: Deleted Doesn't Mean Gone
Here's the part that makes my blood pressure spike. Trezor asked ShipMonk to delete old shipping logs. ShipMonk said it was done. Written assurances. Handled. Except it wasn't.
Those years-old records stayed in ShipMonk's systems anyway. An unauthorized party got in and exfiltrated them. So the "deleted" data wasn't deleted at all. It just moved from a promise to a breach.
The Sept. 4 disclosure says this second batch is roughly 67,000 customers. Add that to the original 13,689 and you're looking at around 80,689 potentially affected. That's a wild jump. Massive. And it all hinges on a vendor's word.
What data are we talking about? Contact and order details. Names, addresses, purchase info. Not seed phrases or private keys. Trezor's been clear on that. The hardware wallets themselves aren't compromised.
But here's the thing: in crypto, your physical address and transaction history are gold for targeted phishing attacks. Scammers can send fake hardware wallets, fake recovery tools, fake "urgent firmware update" emails. They'll know your name, your address, what you bought. That's a brutal social engineering combo.
The Broader Implications: Trust Is The Product
Trezor sells cold storage. The whole sales pitch is "your keys, your coins, your control." But this breach isn't about the devices. It's about the company's operational perimeter. And that's where trust dies.
This isn't just a Trezor problem either. Every crypto company depends on third-party vendors. Shipping providers, email platforms, analytics tools. Each one is an attack surface. Each one can lie about deletion and leave your data sitting in a server room somewhere.
So what's the market's verdict? So far, no panic in Trezor's sales numbers. No major price impact on related tokens. But reputational damage is slower than a price dump. It shows up in support tickets, in forum threads, in "should I switch to another hardware wallet?" posts.
The worst part? Trezor's initial disclosure on Jan. 17 said one thing. This update rewrites it. What else don't we know yet? That's the question traders and customers should be asking. Because today it's 80,689. Tomorrow it could be more.
What You Should Actually Do
Honestly? If you're one of the affected users, treat every email about your Trezor like a trap. No legitimate recovery tool requires you to enter your seed phrase into a website. Ever. No firmware update happens through an email link.
For Trezor owners in general, there's a real lesson here: your physical address is crypto metadata. Once it's out, you can't un-leak it. Be ready for sophisticated phishing that references your actual purchase history.
And for the industry? Stop trusting "we deleted it" without proof. If a vendor can show written confirmation, demand technical verification instead. Ask how deletion is performed. Ask for logs. Ask for audit trails. If they can't provide that, find another vendor.
Trezor got caught trusting a shipping partner. You don't have to make the same mistake.
Traders are watching closely to see if this gets worse before it gets better. But the real takeaway is simpler. In crypto, you're only as safe as the weakest vendor with your data. And right now, that vendor's deletion logs were fiction.
Related Articles
Explore More
Key Terms Explained
An Ethereum Layer 2 that offers native yield on ETH and stablecoins deposited on the chain.
A sudden, significant price drop usually caused by large sell-offs.
A physical device that stores cryptocurrency private keys offline.
A social engineering attack where scammers create fake websites, emails, or messages that look legitimate to steal your credentials or trick you into signing malicious transactions.