Hardware wallet maker Trezor said on Friday that a breach at its shipping provider ShipMonk exposed “another approximately 67,000 US customers,” and that those records were only in ShipMonk’s systems because the company had kept data it had confirmed in writing was deleted.

Trezor said it had “repeatedly requested and received written assurance confirming the deletion of the data.” It added that “we are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” ShipMonk told Trezor on Sept. 2 that the breach was larger than previously stated.

What is out

The newly exposed records cover orders placed between November 2019 and August 2021 and include “full names, shipping addresses, phone numbers, and email addresses,” along with order numbers. Trezor’s original disclosure on Aug. 13 counted 13,689 customers, 11,742 of them with full contact details, on orders placed between May and August of this year. Trezor has not given a combined figure, and the two disclosures could put the exposure above 80,000 records.

What Trezor says is not at risk

“Our systems were not compromised, and your Trezor device is secure,” the company said, adding that private keys and wallet backups were not affected. The risks it flagged are impersonation and, because home addresses are among the exposed fields, physical safety. “Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor,” the company said, adding that the leak “could potentially expose affected individuals to physical security risks.”

Trezor said the exposure is a first for the company. “This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses.” Its customers have been exposed through a third party before: in January 2024 about 66,000 users who had contacted its support desk since December 2021 were put at risk of phishing after a security incident.

Trezor’s advice to affected customers was unchanged from August. “Never enter your wallet backup on a website or share it with anyone.”

Related Listen: Uneasy Money: Inside the AI Agent Scandal That Cheated, Then Covered Its Tracks