Published Security3 min read
Trezor's 90-day retention clause, not its perimeter, is what capped a 13,689-record loss
The hardware wallet maker says its own systems were untouched; its fulfillment provider ShipMonk was hit. A deletion term Trezor pushed into the contract limited what there was to take.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Trezor says the incident did not involve Trezor's systems but rather its third-party shipping provider, ShipMonk.
- Trezor is a hardware crypto wallet provider and says the personal information of nearly 14,000 people was compromised in a data breach.
- Hackers stole the names, addresses, email addresses and phone numbers of 11,742 customers.
- Hackers stole the names, cities and email addresses of 1,947 customers.
- The two affected groups total 13,689 individuals.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Trezor has told customers that an unauthorized actor accessed personal data held by ShipMonk, its third-party shipping provider, and that Trezor's own systems were not compromised [1][2][7]. The exposure covers full names, phone numbers, email addresses and shipping addresses for 11,742 customers, plus names, cities and email addresses for a further 1,947 [3][4] - 13,689 people in total [5].
The detail worth copying is not the incident response. It is the contract. Trezor says the breach was limited by its strict 90-day data storage policy, and that it negotiated the same terms with its fulfillment partners [8]. The affected orders run from May 10 to August 8 [6], a window of exactly 90 days [11], and Trezor was notified of the attack on August 10 [9], two days after that window closed [12]. In other words, the blast radius was set months earlier by a retention term applied to someone else's database, not by anything Trezor's security team did on August 10.
Most companies write deletion obligations for their own stack and then hand a live customer feed to a logistics vendor with no expiry attached. Trezor shared the data with ShipMonk for order delivery purposes [10]. The volume of data that existed to steal on the day of the intrusion was therefore a procurement decision.
That control is not airtight, and Trezor says so. For the 1,947 customers with partial exposure, older orders might have been accessed as well [13]. The company is in direct contact with ShipMonk to establish an exact timeline and determine the full scope [14], which means the 90-day boundary is currently an assertion about intended policy rather than a verified fact about what was in the system. Affected customers span the US, the UK, Sweden, Colombia, Brazil, Italy and Portugal [6], seven jurisdictions [22] with materially different notification regimes.
On the entry point, ShipMonk reportedly notified customers that the attackers accessed data by exploiting a vulnerability in Metabase [15]. SecurityWeek writes that the targeted bug is likely the SQL injection zero-day Metabase patched the week before [16]. The extortion group ShinyHunters has claimed responsibility for an attack on Metabase and, on Wednesday, leaked data it says came from the analytics vendor [17][18]. That is a four-link chain: analytics tool to fulfillment provider to hardware wallet vendor to customer doorstep.
The immediate risk to customers is not their devices. Trezor says the hardware remains secure but that affected customers may be targeted by more sophisticated phishing [7], and it has emailed all impacted customers advising them to be wary of messages requesting personal information or demanding immediate action [19]. A list of confirmed crypto hardware buyers with home addresses and phone numbers is worth more per record than a generic marketing dump, and 11,742 of those records are complete [3].
What to watch: ShipMonk has not publicly acknowledged the incident [20], and it remains unclear how many of its other clients were caught, whether additional individuals' data was taken, and who was behind the attack [21]. Trezor has emailed SecurityWeek's questions onto ShipMonk's plate by proxy; SecurityWeek says it has asked ShipMonk for a statement [23]. Also worth watching is whether any other ShipMonk client can point to a comparable 90-day deletion clause, because the ones that cannot will be reporting larger numbers.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Trezor says the incident did not involve Trezor's systems but rather its third-party shipping provider, ShipMonk.
- [2]
Trezor is a hardware crypto wallet provider and says the personal information of nearly 14,000 people was compromised in a data breach.
ReportedView cited source - [3]
Hackers stole the names, addresses, email addresses and phone numbers of 11,742 customers.
ReportedView cited source - [6]
Customers in the US, the UK, Sweden, Colombia, Brazil, Italy and Portugal who placed orders between May 10 and August 8 were affected.
ReportedView cited source - [7]
Trezor says: "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts."
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut ArghireAug 1414,000 Trezor Customers Impacted by Data Breach at ShipMonk
Additional citations
- Trezor, via SecurityWeek
- Trezor notice
- Trezor
- reported by SecurityWeek
- SecurityWeek



