Invest1 distinct publisher3 min readPublished
The records that expanded Trezor's breach were US orders from 2019 to 2021, held years past the 90-day deletion window its fulfillment partner had promised, which puts the failure in the contract rather than the device.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Trezor's 80,700 against the 13,689 it reported in August is 5.9 times the original count [1][4][15], and the records responsible were US orders placed between November 2019 and August 2021 [3]. Under the 90-day deletion policy Trezor credited in August with keeping the number small [5], even the newest of those orders was due for destruction around November 2021, about four years and ten months before Friday's disclosure [8][17].
The enforcement mechanism, on Trezor's account, was correspondence: it asked ShipMonk more than once for documentation that order data older than 90 days had been deleted, was told each time that it had been, and now says those documents were incorrect [6]. Trezor's own stack held, with no devices, private keys or wallet backups involved and no compromise of its systems [9]. What the record contains is one side of a two-party contract dispute, with no ShipMonk account of the retention and no funds loss traced to the exposure [19].
What a leaked shipping manifest is worth depends on how much verification it saves the buyer. Hacken put phishing and social engineering at $306 million of the $482 million stolen in the first quarter, or 63.5 percent [12][16], and February's wave of forged letters to Trezor and Ledger owners, printed with holograms, QR codes and fake executive signatures [10], is the channel this particular data feeds. David Sehyeon Baek's observation is the operative one: a forged letter carrying a real name and address changes the psychology of the scam [11]. One investor nearly lost $1 million in July by approving a malicious token transaction on Ethereum [14], which is roughly the per-head figure an attacker underwrites against.
The counter-thesis, and it is not a weak one, is that names and addresses are commodity data traded and leaked continuously, so the marginal harm is thinner than 80,700 sounds; the scarce field in this file is the confirmation that the addressee bought a hardware wallet. It thickens in one direction. Trezor's January 2024 disclosure covered about 66,000 customers who had contacted support since December 2021 [13], so the two published sets total roughly 146,700 records with an overlap nobody has quantified [18].
The practical alternatives here are both dull: contractual audit rights that require deletion evidence rather than an affirmative reply, or narrowing what the fulfillment partner ever receives, which is awkward when a physical device has to reach a doorstep. The reading that this is a retention failure rather than a wallet failure breaks in two places worth watching. If ShipMonk documents that the surviving records sat in a backup outside the scope of the deletion term, the story becomes a drafting problem instead of a broken promise; and if a third revision follows the first two, the finding is that Trezor could not size its own customer exposure without its vendor's cooperation [7].
Ranked by verification strength, evidence, and original report placement.
Trezor said the ShipMonk breach exposed data from another 67,000 U.S. users, bringing the total potentially affected to roughly 80,700.
In August, Trezor estimated exposure at about 14,000 people; its FAQ puts the initially reported figure at 13,689.
When Trezor announced the leak in August, the 90-day data deletion policy implemented by its fulfillment partner was credited with limiting the number of impacted users.
Trezor said it asked ShipMonk multiple times for documentation showing that order data older than 90 days had been deleted, received positive answers every time, and that those documents turned out to be incorrect.
Exposed information includes names, addresses, phone numbers, email addresses and order details, but not private keys or wallet backups.
The new batch of data involves orders placed by U.S. customers between November 2019 and August 2021, according to Trezor's post on X.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.1 distinct publisher
invest
A hardware wallet's real attack surface is its order database, not its air gap4 distinct publishers
security
Attackers bought five working browser extensions and shipped malware through auto-update1 distinct publisher
product
SafePal's breach came through an order-tracking plug-in, and that is the point3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet relaying one company's post
Every figure here — 67,000, 80,700, 13,689, the November 2019 to August 2021 window — comes from a single Trezor post on X, relayed by Cryptopolitan, with the baseline filled in from Trezor's FAQ. A company is a legitimate primary source for its own customer counts, which keeps this from scoring low. What keeps it from scoring well is that the load-carrying part, the story of deletion documents that were wrong, has no second witness: no filing, no audit, no ShipMonk response.
Records confirmed loose, harm not on the record
Two dated events anchor this: the vendor's report to Trezor around September 2 and the public update on September 4. What follows from them is unrecorded. There's no phishing wave traced to these records, no theft attributed to them, and no count of customers notified. February's forged-letter campaign shows the attack this list would serve, but it predates the disclosure and cannot be pinned to it.
Loss totals borrowed from elsewhere
"Explodes" describes a revised count, and the money that gives the piece its weight belongs to other incidents: Hacken's $306 million of $482 million in first-quarter theft and one investor's near-loss of $1 million on a malicious approval, neither connected to these 80,700 records. The escalation underneath is real enough — the count grew roughly sixfold and the 90-day policy that justified the small original number turned out not to have been applied — so the overstatement is in the framing, not the facts.
The sole narrator names the culprit
Trezor is the breached brand, the only witness on record, and the one assigning fault, and the account it offers, repeated requests, positive answers each time, documents that proved incorrect, places the failure squarely with its fulfillment partner. ShipMonk, which would have reason to characterise its retention practices differently, says nothing in this reporting. Cryptopolitan's page carries the usual crypto-desk furniture of a newsletter pitch and an investment disclaimer.
Firm on counts, blind on the vendor's side
The customer numbers and the order window are about as solid as a company's own disclosure gets, and the arithmetic on top of them holds: August 2021 orders were due for deletion around November 2021, four years and ten months before Friday's post. Why the data survived is another matter, told by one side only, so treat the mechanism as provisional even where the counts are not.