Sep 8
/
Latest News
Trezor Warns 67,000 More Customers Exposed in ShipMonk Breach, Heightening Phishing and Physical Security Risks
SatoshiLabs has warned that roughly 67,000 additional Trezor customers are now at heightened risk of phishing attacks after attackers accessed and exposed their names, email addresses, phone numbers, and shipping addresses during the August 2026 breach at ShipMonk, the company that ships Trezor wallets.
The Czech-based hardware wallet maker said the leaked information could be used for scam emails, fraudulent calls, physical letters, and potentially expose affected individuals to physical security risks. The breach occurred at ShipMonk, which handles Trezor shipments, after attackers exploited an SQL injection zero-day in Metabase's Cloud SaaS platform.
According to SatoshiLabs, ShipMonk failed to delete or anonymize customer data after 90 days, despite contractual requirements. As a result, orders delivered to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026 were exposed, affecting 3,889 customers. In an update last week, SatoshiLabs confirmed that attackers also accessed full shipping data for approximately 67,000 additional US-based customers who placed orders between November 2019 and August 2021.
SatoshiLabs said it repeatedly requested and received written assurances from ShipMonk confirming deletion of customer data, and expressed disappointment that the data remained in ShipMonk's systems. The company has emailed all affected customers, warning them to watch for scam attempts and suspicious account activity.
SatoshiLabs confirmed that its own systems were not compromised and that Trezor devices remain secure. The company said it is working on offering anonymous delivery options, including dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery.
In the meantime, customers who want to reduce the risk of exposure are advised to use anonymous email addresses, pay with cryptocurrency or disposable digital cards, and use P.O. Boxes for delivery.
Several customers have reported receiving phishing calls and QR phishing letters following the breach. SatoshiLabs said this is the first time since Trezor was founded in 2013 that customer phone numbers and shipping addresses have been exposed, and acknowledged the seriousness of the incident.
Blockchain analytics firm Chainalysis recently reported a surge in violent attacks targeting crypto holders. As crypto adoption has grown, criminals have increasingly targeted individuals who may hold large amounts of cryptocurrency accessible via smartphones or hardware wallets. Chainalysis estimates that violent criminals have extracted more than $30 million from holders so far this year, and warned that 2026 may become the worst year on record for violent crypto attacks.
Experts advise crypto users not to disclose their holdings publicly and to use decoy or duress wallets, hidden wallets with passphrases, and multi-signature authorization setups to reduce risk.
The Czech-based hardware wallet maker said the leaked information could be used for scam emails, fraudulent calls, physical letters, and potentially expose affected individuals to physical security risks. The breach occurred at ShipMonk, which handles Trezor shipments, after attackers exploited an SQL injection zero-day in Metabase's Cloud SaaS platform.
According to SatoshiLabs, ShipMonk failed to delete or anonymize customer data after 90 days, despite contractual requirements. As a result, orders delivered to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026 were exposed, affecting 3,889 customers. In an update last week, SatoshiLabs confirmed that attackers also accessed full shipping data for approximately 67,000 additional US-based customers who placed orders between November 2019 and August 2021.
SatoshiLabs said it repeatedly requested and received written assurances from ShipMonk confirming deletion of customer data, and expressed disappointment that the data remained in ShipMonk's systems. The company has emailed all affected customers, warning them to watch for scam attempts and suspicious account activity.
SatoshiLabs confirmed that its own systems were not compromised and that Trezor devices remain secure. The company said it is working on offering anonymous delivery options, including dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery.
In the meantime, customers who want to reduce the risk of exposure are advised to use anonymous email addresses, pay with cryptocurrency or disposable digital cards, and use P.O. Boxes for delivery.
Several customers have reported receiving phishing calls and QR phishing letters following the breach. SatoshiLabs said this is the first time since Trezor was founded in 2013 that customer phone numbers and shipping addresses have been exposed, and acknowledged the seriousness of the incident.
Blockchain analytics firm Chainalysis recently reported a surge in violent attacks targeting crypto holders. As crypto adoption has grown, criminals have increasingly targeted individuals who may hold large amounts of cryptocurrency accessible via smartphones or hardware wallets. Chainalysis estimates that violent criminals have extracted more than $30 million from holders so far this year, and warned that 2026 may become the worst year on record for violent crypto attacks.
Experts advise crypto users not to disclose their holdings publicly and to use decoy or duress wallets, hidden wallets with passphrases, and multi-signature authorization setups to reduce risk.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.