Trezor, the Czech hardware-wallet maker, said on Friday 4 September that a data breach at its US shipping contractor ShipMonk is almost six times larger than it disclosed in August — about 80,700 people against 13,689 —, because ShipMonk was still holding customer order records from a contract that ended in 2021. The updated notice on Trezor’s blog says the company was informed on 2 September that the leaked data “also contained order data from our prior cooperation between November 2019 and August 2021,” affecting “another approximately 67,000 US customers” with full exposure: name, email address, phone number, shipping address and order number. Bloomberg and The Block carried the figure the same morning. Trezor’s original 13 August disclosure covered 11,742 customers with full exposure and 1,947 with partial exposure — 13,689 in all; the full-exposure records came from orders delivered between 10 May and 8 August 2026 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. (the partial-exposure records, Trezor said on 14 August, include some older orders). Adding Friday’s 67,000 puts the total at approximately 80,700 people. Every affected customer has been emailed from help@trezor.io, Trezor says; anyone who has not received that email is not in the set.

The sentence that matters in Friday’s update is not the number. It is this one: “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.” Trezor’s August notice had leaned on its 90-day retention rule to bound the damage — the company requires fulfilment partners to delete or anonymise order data 90 days after delivery, and told customers that “older orders were no longer held in ShipMonk systems and could not be exposed.” That sentence was written in good faith and turned out to be false, not because the policy was wrong but because a contractor did not do what it had certified in writing that it had done. The 2019–2021 records had been due for deletion, on the 90-day rule, by late 2021. They sat for four to five more years.

What leaked, what did not, and why the distinction is the whole story

Nothing about the wallets themselves is affected. Trezor’s notice is explicit: “our systems were not compromised, and your Trezor device is secure,” and, in its FAQ, “The contents of the parcel were not exposed in this breach.” A hardware wallet’s security model does not depend on the manufacturer or its contractors keeping any secret: the private keys are generated on the device, the recovery backup is written down by the owner, and neither ever passes through a shipping database. That model held. What leaked is the other thing a hardware-wallet company necessarily knows about you — that you bought one, and where to send it. Cyber Security News, which has followed the incident since August, reports that ShipMonk told its customers the attackers exploited a vulnerability in Metabase, an analytics tool, and that Metabase had notified ShipMonk on 6 August that an unauthorised party had reached account and customer data. ShipMonk informed Trezor on 10 August; Trezor published on 13 August.

The reason a list of names and addresses is a serious leak for this product and a minor one for most others is that it is a list of people who own an asset that can be taken with a key and a threat rather than with a bank. Trezor’s own update names the two risks in order: “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.” The first is by far the more likely and has a known playbook — a letter or call, on Trezor letterhead or from a “support agent,” that walks the customer into typing their recovery words into a website. Trezor’s standing instruction, repeated in bold in the notice, is the only defence that matters: “Never enter your wallet backup on a website or share it with anyone.” The second risk is rarer and the one a shipping address makes possible. Our field guide today walks through how to read a notice like this one line by line, and what an affected customer can actually do about each risk.

Two details in the notice are worth reading twice. First, Trezor describes the new tranche as US customers only; the seven-country list applies to the May–August 2026 orders, and the notice does not say whether the 2019–2021 contract covered other countries. Second, Trezor says this is “the first time since Trezor was founded in 2013” that a breach has exposed customer phone numbers and shipping addresses. The company that has had the longest run in this product category without such a leak has now had one that reaches back almost seven years, through no failure of its own systems, which is the most useful single sentence about supply-chain risk a self-custody reader will get this month.

What Trezor is changing, and the timeline it has put in writing

The notice lists four ways to order more privately today — an email address not linked to your identity, paying in crypto or with a disposable card, a P.O. box (with the caveat that USPS will still hold an ID) — and one that is not yet available: an “Anonymous Delivery” option with a dedicated checkout, locker pickup, neutral packaging, generic sender details and “automatic deletion of shipping identifiers after delivery.” Trezor wrote in August that it aims to have that option live “in the EU by September 2026 and in the US by the end of 2026.” Cyber Security News reports the company is preparing it. The EU date is this month; whether it is met is one of the two things we mark below.

For the market this is not a price story and we will not make it one. Bitcoin closed Saturday at $79,830.42 on Bitstamp, up 0.193%, in a $722 range that was the tenth-narrowest of 248 sessions this year; today’s markers piece has the weekend numbers, including the difficulty retarget that settled two of our open claims on Saturday night. But a breach of this kind is a self-custody story in the strict sense, and the site’s readers who hold coins on a device bought from any manufacturer since 2019 should treat this weekend’s inbox and letterbox with more suspicion than usual whether or not they received Trezor’s email — because the scam letters will not be addressed only to people on the list.

The marker

As standing practice we mark one falsifiable claim on this story. R1: on or before Wednesday 30 September 2026, Trezor’s breach notice at trezor.io is updated a further time with a higher affected-customer count than the approximately 80,700 (13,689 plus approximately 67,000) disclosed as of 4 September. The reasoning is that the notice has already been corrected twice — on 14 August, when the partial-exposure records turned out to include older orders (the count did not change), and on 4 September, when it did — and that a contractor which retained one expired dataset against written assurance may be found to have retained others; the counter-argument is that ShipMonk’s investigation is a month old and the 2019–2021 tranche may be the last of it. If it grades as a fail, the 4 September population was the full population and the desk over-read two corrections as a pattern. A second, separate claim sits in the field guide. We will grade R1 against the notice’s own text, not against press reports.

Sources: Trezor’s notice, first published 13 August 2026 and updated 14 August and 4 September; Bloomberg, 4 September; The Block, 4 September; Cyber Security News, 4 September. Quotations are verbatim from Trezor’s notice as read at 06:10 UTC on 6 September. Our earlier guides on choosing a hardware wallet and on where a seed’s security actually comes from explain why the device model survives a leak like this one.

Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR. Do your own research and consult a licensed financial advisor before making investment decisions.