Invest2 distinct publishers3 min readPublished Updated
The records that expanded Trezor's breach were US orders from 2019 to 2021, held years past the 90-day deletion window its fulfillment partner had promised, which puts the failure in the contract rather than the device.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Trezor's 80,700 against the 13,689 it reported in August is 5.9 times the original count [1][4][15], and the records responsible were US orders placed between November 2019 and August 2021 [3]. Under the 90-day deletion policy Trezor credited in August with keeping the number small [5], even the newest of those orders was due for destruction around November 2021, about four years and ten months before Friday's disclosure [8][17].
The enforcement mechanism, on Trezor's account, was correspondence: it asked ShipMonk more than once for documentation that order data older than 90 days had been deleted, was told each time that it had been, and now says those documents were incorrect [6]. Trezor's own stack held, with no devices, private keys or wallet backups involved and no compromise of its systems [9]. What the record contains is one side of a two-party contract dispute, with no ShipMonk account of the retention and no funds loss traced to the exposure [19].
What a leaked shipping manifest is worth depends on how much verification it saves the buyer. Hacken put phishing and social engineering at $306 million of the $482 million stolen in the first quarter, or 63.5 percent [12][16], and February's wave of forged letters to Trezor and Ledger owners, printed with holograms, QR codes and fake executive signatures [10], is the channel this particular data feeds. David Sehyeon Baek's observation is the operative one: a forged letter carrying a real name and address changes the psychology of the scam [11]. One investor nearly lost $1 million in July by approving a malicious token transaction on Ethereum [14], which is roughly the per-head figure an attacker underwrites against.
The counter-thesis, and it is not a weak one, is that names and addresses are commodity data traded and leaked continuously, so the marginal harm is thinner than 80,700 sounds; the scarce field in this file is the confirmation that the addressee bought a hardware wallet. It thickens in one direction. Trezor's January 2024 disclosure covered about 66,000 customers who had contacted support since December 2021 [13], so the two published sets total roughly 146,700 records with an overlap nobody has quantified [18].
The practical alternatives here are both dull: contractual audit rights that require deletion evidence rather than an affirmative reply, or narrowing what the fulfillment partner ever receives, which is awkward when a physical device has to reach a doorstep. The reading that this is a retention failure rather than a wallet failure breaks in two places worth watching. If ShipMonk documents that the surviving records sat in a backup outside the scope of the deletion term, the story becomes a drafting problem instead of a broken promise; and if a third revision follows the first two, the finding is that Trezor could not size its own customer exposure without its vendor's cooperation [7].
Ranked by verification strength, evidence, and original report placement.
Trezor said the ShipMonk breach exposed data from another 67,000 U.S. users, bringing the total potentially affected to roughly 80,700.
Exposed information includes names, addresses, phone numbers, email addresses and order details, but not private keys or wallet backups.
The new batch of data involves orders placed by U.S. customers between November 2019 and August 2021, according to Trezor's post on X.
In August, Trezor estimated exposure at about 14,000 people; its FAQ puts the initially reported figure at 13,689.
When Trezor announced the leak in August, the 90-day data deletion policy implemented by its fulfillment partner was credited with limiting the number of impacted users.
Trezor said it asked ShipMonk multiple times for documentation showing that order data older than 90 days had been deleted, received positive answers every time, and that those documents turned out to be incorrect.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.1 distinct publisher
security
A machine found the bug and set the clock: Ledger disputes TestMachine's timeline1 distinct publisher
invest
A hardware wallet's real attack surface is its order database, not its air gap4 distinct publishers
invest
Coinkite now makes Coldcard owners roll dice, after $130M walked out of air-gapped wallets1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One post, retold twice
Every figure in this story traces to a single Trezor post on X dated September 4. Cryptopolitan embeds that post and supplies the 13,689 baseline in its FAQ; Cointelegraph paraphrases the same update hours earlier. The counts, the order window and the data categories are precise and internally consistent, which keeps this above the middle. What holds it down is the central assertion: that ShipMonk's deletion documentation was incorrect is Trezor's reading of documents no reporter has seen, and ShipMonk is quoted nowhere in our coverage.
Exposure dated, use unobserved
Exposure is confirmed and dated: ShipMonk's finding reached Trezor on September 2 and the revised total was public two days later. Use of the data is not. Neither report attaches stolen funds, a phishing wave, or a complaint to the 80,700 records. The February forged letters and the July Ethereum approval loss are precedents from the same threat pattern, not consequences of this list, and both publishers present them that way.
Risk framing runs past the record
Neither publisher inflates the counts; Trezor revised its own figure upward, against its interest, and a move from 13,689 to 80,700 needs no adjective. The stretch is in the chain built around it. Cryptopolitan runs a section headed on how a mailing list becomes a weapon and then sets Hacken's $306 million quarter and a $1 million Ethereum approval loss beside a list that nothing in the reporting connects to either. Cointelegraph is the more restrained of the two, naming seed-phrase theft as the mechanism and stopping there.
The unquoted partner carries the blame
Trezor is the only narrator, and the account it gives lands the failure on a partner that neither report quotes or shows being asked. That serves the vendor twice over: devices and keys were untouched, and the deletion promise was somebody else's to keep. Both outlets write for wallet owners rather than for logistics buyers, and Cryptopolitan closes with a newsletter pitch and an investment disclaimer. What Trezor's own contract, audit rights or state notification duties required of it goes unexamined by both.
Solid counts, one-sided cause
Counts, the order window and the categories of leaked data are Trezor describing its own customers, and those tend to hold. The characterisation of ShipMonk's assurances is one side of what looks like a contract dispute and could read differently if ShipMonk answers. Two outlets working from one post is agreement rather than corroboration, which caps this in the low sixties.