Another 67,000 Trezor customers had their personal data stolen, and some of them are only finding out right now.

Trezor has confirmed that a previously unidentified batch of customer records was compromised in the ShipMonk logistics breach, bringing the total number of affected users far higher than initially disclosed. The newly surfaced records span 2019 to 2021 and include full names, email addresses, phone numbers, shipping addresses, and order numbers.

Let that sink in. This data has potentially been sitting in the wrong hands for up to six years.

What Actually Happened

ShipMonk is a third-party fulfillment and logistics provider that Trezor used to handle hardware wallet shipments. When the breach was first reported, the damage appeared contained. It was not. Trezor's latest disclosure reveals a second wave of affected records that nearly doubles the known victim count.

The exposed data does not include passwords, seed phrases, or private keys. Your crypto is not directly at risk from this breach alone. But that framing undersells the real danger.

Why This Is More Serious Than It Sounds

A name plus a shipping address plus a phone number is a phishing kit. Trezor users are high-value targets by definition. Anyone who bought a hardware wallet is signaling one thing loudly: they hold enough crypto to care about securing it.

That makes this leaked data a roadmap for social engineering attacks. Scammers can call, text, or email victims while referencing real order details to appear legitimate. They will claim your device is compromised. They will offer to help you "migrate" your funds. They will ask for your seed phrase.

This playbook is not hypothetical. Trezor users were targeted with exactly this type of attack following the 2022 Mailchimp breach, where a phishing campaign used leaked customer data to impersonate Trezor support.

What Trezor Is Saying

Trezor says it has notified affected customers and is working with ShipMonk to understand the full scope of the exposure. The company is emphasizing that wallet security itself remains intact. No cryptographic data was accessed.

What You Should Do Right Now

If you purchased a Trezor device between 2019 and 2021, treat any inbound communication referencing your order as suspicious until proven otherwise. Trezor will never ask for your seed phrase, full stop.

Beyond that, this breach is a reminder of a structural problem the hardware wallet industry has not solved. The devices protect your keys. The companies selling them still rely on conventional e-commerce infrastructure that carries conventional data risks.

Watch for a spike in Trezor-branded phishing attempts over the coming weeks. The data is out there, and someone will use it.