Karl_3000 (OP)
Full Member
 

Activity: 406
Merit: 206
I’m drunk on bitcoin
|
 |
September 04, 2026, 11:48:21 AM |
|
This is what Trezor posted on X few hours ago, that nother 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed. https://x.com/Trezor/status/2095807665603584085Furthermore according to Trezor: Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
|
|
|
|
Upgrade00
Legendary

Activity: 2870
Merit: 2949
Community Manager - Brand Promotions ✅
|
 |
September 04, 2026, 12:20:21 PM |
|
At this point,when communicating such breaches they should not include the part that says users that do not get ang emails from them on the breach are safe, this creates a false sense of security. Everyone who has sent them data at any point in time should highly consider that it could have been leaked through their systems or a third party as in this case and take precautionary measures to protect themselves from any scam attempt that could result from that.
|
| . .Duelbits..REWARDING, BEYOND LIMITS... | █████████████████████████ █████████████████████████ ███████████▀▀░░▀█▄░░▀████ ████████▀░░░░░░░░▀█▄░████ ███████░░░░▄▄░░▄░░░▀█████ ██████░░░░░▀▀▄██▀░░░░████ █████░░░██░▄██▀▄▄░░░█████ ████░░░░░▄██▀░░▀▀░░██████ █████▄░░▀█▀░██░░░░███████ ████░▀█▄░░░░░░░░▄████████ ████▄░░▀█▄░░▄▄███████████ █████████████████████████ █████████████████████████ | █████████████████████████ █████████████████████████ █████████▀░░▀░███████████ ████████░░░▄░█░██████████ ███████████▌▐██░█████████ ███████████░███▌▐████████ ██████████░█████░████████ ██████▀░▄░▀███▀░▄░▀██████ █████░▄▀░░░░█░▄▀░░░░█████ █████░░░░░░░█░░░░░░░█████ ██████▄░░░▄███▄░░░▄██████ █████████████████████████ █████████████████████████ | █ █ █ █ █ █ █ █ █ █ █ █ █ | |
| | █ █ █ █ █ █ █ █ █ █ █ █ █ | PLAY NOW |
|
|
|
PX-Z
Legendary

Activity: 2296
Merit: 1374
Wallet Transaction Notifier - @txnNotifierBot
|
 |
September 04, 2026, 12:31:40 PM |
|
What a disappointment. They should just use their own provider or make one for their ecom and shipping rather than relying on irresponsible third parties. And instead of a 90-day data retention policy, they should make it lower.
Anyway, another set of phishing emails, smishing is on the way. smh
|
|
|
|
Karl_3000 (OP)
Full Member
 

Activity: 406
Merit: 206
I’m drunk on bitcoin
|
 |
September 04, 2026, 12:33:31 PM |
|
At this point,when communicating such breaches they should not include the part that says users that do not get ang emails from them on the breach are safe, this creates a false sense of security. Everyone who has sent them data at any point in time should highly consider that it could have been leaked through their systems or a third party as in this case and take precautionary measures to protect themselves from any scam attempt that could result from that.
It is very bad that ShipMonk did not delete the Trezor customers data, I will also say that no hardware customers should be believe that their information has not be leaked, including Trezor, Ledger and other hardware wallets users. I think many bad people from France will be happy to have the one for their country people to get leaked so that they can buy the data and be used to carry out some wrenches attacks. What a disappointment. They should just use their own provider or make one for their ecom and shipping rather than relying on irresponsible third parties. And instead of a 90-day data retention policy, they should make it lower.
Trezor want to introduce anonymous shipping instead.
|
|
|
|
PX-Z
Legendary

Activity: 2296
Merit: 1374
Wallet Transaction Notifier - @txnNotifierBot
|
 |
September 04, 2026, 01:03:56 PM |
|
Trezor want to introduce anonymous shipping instead.
It sounds like assuring and a solution but i don't think it will be smoothly implemented especially countries who has strict or just implemented consumer act. For instances, return and refunds, also for frauds or fake items receives. How it will be effective if the receiver is anonymous or just using alias or what. Its much more complex if i will think it more deeply actually.
|
|
|
|
coinlary
Sr. Member
  

Activity: 770
Merit: 284
Make decisions without looking back
|
 |
September 04, 2026, 03:08:06 PM |
|
Now everyone will even understand why you shouldn't trust anything you can't handle or can't be reviewed by the whole public. So now all this mess in not really on Trezor even though they are to be blamed in some specific aspect . If anyone should sue trezor for losing money then they can also sue Shipmonk if they truly had a signed agreement to delete every customers details after every shippin(according to their data policy) but refused to honor the agreement. Still don't get why the company had almost 7 years data sitting in their database  . This is very bad and ridiculous at the same time
|
|
|
|
salad daging
Legendary

Activity: 2506
Merit: 1066
Bitcoin To The Moon 📈📈📈
|
 |
September 04, 2026, 08:04:37 PM |
|
Until this incident had Trezor decided to stop cooperating with ShipMonk? If continuing to use this sender service does not rule out that new cases will continue to appear where emails will leak, I think this is ShipMonk's fault for not deleting customer data.
I am curious about the anonymous sending that Trezor does, this platform has received hardware messages from time to time, well whether this sending has been done or is still in the development stage because there is no announcement of anything.
|
|
|
|
Z-tight
Legendary

Activity: 1708
Merit: 1325
|
 |
September 04, 2026, 11:26:08 PM |
|
Just when Ledger is geting sued for ~ $500m for data and security breach that made a customer lose nearly $2m, Trezor break further bad news that more data was stolen than we originally thought. It is safe to say that this is not a good period for hardware wallet manufacturers and users, if we include the recent Coldcard hack. I cannot understand why their logistics partner, ShipMonk would lie to them about deleting all Trezor's customer data at the end of their first cooperation (2019-2021), but still had it stored somewhere in their system, to what end? Or just an oversight.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
Meuserna
|
 |
September 05, 2026, 01:10:38 AM Merited by vapourminer (1) |
|
It is very bad that ShipMonk did not delete the Trezor customers data, I will also say that no hardware customers should be believe that their information has not be leaked, including Trezor, Ledger and other hardware wallets users.
Ledger did leak theirs. All of it, including over a million customer names, physical addresses and phone numbers: "Ledger wallet users face mounting home invasion and other scareware threats as hacker dumps private customer information online."
SOURCE: Cointelegraph "In June 2020, the hardware crypto wallet manufacturer Ledger suffered a data breach that exposed over 1 million email addresses. The data was initially sold before being dumped publicly in December 2020 and included names, physical addresses and phone numbers. The data was provided to HIBP by Alon Gal, CTO of cybercrime intelligence firm Hudson Rock." SOURCE: Pwned https://haveibeenpwned.com/Breach/LedgerThese days, the safest way to buy a hardware wallet is at a physical store, like Best Buy. Pay in cash. Or, do what I do: Use open source firmware that runs on off the shelf hardware, such as ShieldSigner, which runs on a Raspberry Pi, or Krux, which runs on K210 devices.
|
|
|
|
m2017
Legendary
Online
Activity: 2604
Merit: 1718
keep walking, Johnnie
|
 |
September 05, 2026, 07:54:50 AM |
|
What a disappointment. They should just use their own provider or make one for their ecom and shipping rather than relying on irresponsible third parties.
However, this doesn't offer a 100% guarantee of secure data storage. That said, I agree that a proprietary solution from trezor would benefit their clients: in the event of a leak, trezor would not be able to shift the blame to others, the full responsibility would rest with them, thereby compelling them to take a very serious approach to implementing their own e-commerce solution. And instead of a 90-day data retention policy, they should make it lower.
Trezor has floated the concept of anonymous delivery. We are awaiting the full announcement (it will be interesting to see how this is actually implemented). However, I have doubts that this "feature" will be supported in all countries where delivery is available. It seems to me that shortening the data retention period from 90 days to, say, 45 or 30 days would be entirely feasible (without compromising the service provided), as most typical disputes (such as refund requests) can be resolved within that timeframe. With a 90-day window, buyers have no choice but to hope that their personal data won't be leaked before it gets wiped. Anyway, another set of phishing emails, smishing is on the way. smh
It would be good if it were limited to just that, rather than a "visit from guests with a $5 wrench".
|
|
|
|
ABCbits
Legendary

Activity: 3724
Merit: 10358
|
 |
September 05, 2026, 08:48:26 AM Merited by vapourminer (1) |
|
Furthermore according to Trezor: Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
If Trezor want to keep their reputation, i think they should both stop working together with ShipMonk and also sue ShipMonk for violating their contract. These days, the safest way to buy a hardware wallet is at a physical store, like Best Buy. Pay in cash.
I see Best Buy is one of Trezor authorized reseller[1]. But do you know that Trezor actually sold on their physical store, rather than only their online store? I don't find such information either from Trezor or Best Buy website. [1] https://trezor.io/resellers
|
|
|
|
Z-tight
Legendary

Activity: 1708
Merit: 1325
|
 |
September 05, 2026, 09:15:19 AM Merited by vapourminer (1) |
|
If Trezor want to keep their reputation, i think they should both stop working together with ShipMonk and also sue ShipMonk for violating their contract.
They didn't actually violate their contract. ShipMonk were not contractually obligated to delete Trezor's customer data during their first cooperation with the hardware wallet company, that cooperation lasted from 2019-2021, and so i'm not surprised that it is the data from that period that was exposed. However, after the end of their first cooperation, Trezor requested that ShipMonk should delete the information, even if they were not initially obligated to, and they confirmed that they had deleted it, but it turns out that it was a lie. I believe it was after their first cooperation (2019-2021), that the 90-day retention policy applied in their cooperation with the logistics company.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
Karl_3000 (OP)
Full Member
 

Activity: 406
Merit: 206
I’m drunk on bitcoin
|
 |
September 05, 2026, 03:40:17 PM |
|
It sounds like assuring and a solution but i don't think it will be smoothly implemented especially countries who has strict or just implemented consumer act. For instances, return and refunds, also for frauds or fake items receives. How it will be effective if the receiver is anonymous or just using alias or what. Its much more complex if i will think it more deeply actually. I also do not know yet how Trezor is going to achieve this successfully and I am being sarcastic anytime I am talking about it with people. But I will be patient to see if Trezor will convince us. Until this incident had Trezor decided to stop cooperating with ShipMonk? If continuing to use this sender service does not rule out that new cases will continue to appear where emails will leak, I think this is ShipMonk's fault for not deleting customer data. Anyone that want privacy should not buy a hardware wallet unless the a among shipping is true and truly privacy. If the shipping is given to another company, that does not mean the new company is perfect from protecting customers data. If Trezor want to keep their reputation, i think they should both stop working together with ShipMonk and also sue ShipMonk for violating their contract.
They didn't actually violate their contract. ShipMonk were not contractually obligated to delete Trezor's customer data during their first cooperation with the hardware wallet company, that cooperation lasted from 2019-2021, and so i'm not surprised that it is the data from that period that was exposed. However, after the end of their first cooperation, Trezor requested that ShipMonk should delete the information, even if they were not initially obligated to, and they confirmed that they had deleted it, but it turns out that it was a lie. I believe it was after their first cooperation (2019-2021), that the 90-day retention policy applied in their cooperation with the logistics company Trezor told ShipMonk to delete their customers data, ShipMonk said they have deleted it. Trezor can sue ShipMonk.
|
|
|
|
Z-tight
Legendary

Activity: 1708
Merit: 1325
|
 |
September 05, 2026, 04:22:28 PM |
|
Trezor told ShipMonk to delete their customers data, ShipMonk said they have deleted it. Trezor can sue ShipMonk.
Sue them you say, based on a breach of what agreement? What they had was a gentleman agreement, there was no contractual obligation from ShipMonk to do what Trezor requested and that is what i have just explained. If the data breach affected users from the period the 90-day retention policy became a part of their contract, then there are legal grounds for a lawsuit.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
salad daging
Legendary

Activity: 2506
Merit: 1066
Bitcoin To The Moon 📈📈📈
|
 |
September 05, 2026, 10:20:59 PM |
|
Until this incident had Trezor decided to stop cooperating with ShipMonk? If continuing to use this sender service does not rule out that new cases will continue to appear where emails will leak, I think this is ShipMonk's fault for not deleting customer data. Anyone that want privacy should not buy a hardware wallet unless the a among shipping is true and truly privacy. If the shipping is given to another company, that does not mean the new company is perfect from protecting customers data. Anonymous shipping now his kayak is still not available, I do not know now how user bought his Trezor shipping does it keep using third party anymore for shipping other than ShipMonk?  After all this does happen for the United States, and several other countries, parts of Asia are not affected still by this incident people will be more vigilant again or until waiting for this anonymous delivery is really widespread throughout the world which is done by Trezor.
|
|
|
|
ABCbits
Legendary

Activity: 3724
Merit: 10358
|
 |
Today at 07:01:04 AM |
|
If Trezor want to keep their reputation, i think they should both stop working together with ShipMonk and also sue ShipMonk for violating their contract.
They didn't actually violate their contract. ShipMonk were not contractually obligated to delete Trezor's customer data during their first cooperation with the hardware wallet company, that cooperation lasted from 2019-2021, and so i'm not surprised that it is the data from that period that was exposed. However, after the end of their first cooperation, Trezor requested that ShipMonk should delete the information, even if they were not initially obligated to, and they confirmed that they had deleted it, but it turns out that it was a lie. I believe it was after their first cooperation (2019-2021), that the 90-day retention policy applied in their cooperation with the logistics company. Their blog indirectly imply their old contract state/require 90-day retention on ShipMoon side. It also contained order data from our prior cooperation between November 2019 and August 2021.
Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.
Is there different part of that blog post (that i missed) or other source that claim/mention their old contract doesn't include 90-day retention?
|
|
|
|
Z-tight
Legendary

Activity: 1708
Merit: 1325
|
 |
Today at 01:11:50 PM |
|
Is there different part of that blog post (that i missed) or other source that claim/mention their old contract doesn't include 90-day retention?
Yes. Trezor confirmed in X that they actually made the request to ShipMonk to delete the data of their customers, and that ShipMonk themselves confirmed, through written communication that they had honored the request. However, they also made it known that it was not part of their initial contract. You can find the information below, or the full communication on X, in the thread where they broke the news. 
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
Karl_3000 (OP)
Full Member
 

Activity: 406
Merit: 206
I’m drunk on bitcoin
|
 |
Today at 01:19:31 PM |
|
Yes. Trezor confirmed in X that they actually made the request to ShipMonk to delete the data of their customers, and that ShipMonk themselves confirmed, through written communication that they had honored the request. However, they also made it known that it was not part of their initial contract. You can find the information below, or the full communication on X, in the thread where they broke the news.  Just forget about the contractually or not contractually that you are talking about, if what ShipMonk did affected Trezor, ShipMonk can be sued. If you have been to some court cases, you will understand what I am saying. As long as they are working together and Trezor has the evidence that they told ShipMonk and there is evidence that ShipMonk said they have deleted it but did not delete it. It can result to lawsuit.
|
|
|
|
Wind_FURY
Legendary

Activity: 3766
Merit: 2225
|
 |
Today at 01:47:12 PM |
|
This is what Trezor posted on X few hours ago, that nother 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed. https://x.com/Trezor/status/2095807665603584085Furthermore according to Trezor: Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems. Would it be logical to make a presumption that ShipMonk sells customer data that they receive to third-parties? 🤔 Because Trezor received "written assurance" that confirms deletion of data, and that it's in their contract suggests that ShipMonk should be investigated.
|
| .SHUFFLE.COM.. | ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ | ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ ███████████████████████ | . ...Next Generation Crypto Casino... |
|
|
|
Lucius
Legendary

Activity: 4088
Merit: 7758
A swap that needs a hand? zeto.cash@proton.me
|
 |
Today at 01:56:10 PM |
|
Would it be logical to make a presumption that ShipMonk sells customer data that they receive to third-parties?
🤔
Because Trezor received "written assurance" that confirms deletion of data, and that it's in their contract suggests that ShipMonk should be investigated.
The question arises as to why they would otherwise keep data that they claim to have been deleted even in writing? We can assume that they are just careless and that someone in that company is not doing their job - or that they had other plans with that data that they may have used in the meantime. It's a bit strange to me that someone was obviously looking for that data, even though it was officially claimed for years that it had been deleted - which could mean that there was information from the inside that the data still exists. I will say that all those who in the 21st century continue to keep databases unencrypted should be banned for life from performing any work related to data processing and storage.
|
|
|
|
|