Better tools. Better news.
Friday, September 4, 2026 · UTC
95 of 1624 in this edition
crypto

Trezor Data Breach Widens: 67,000 More U.S. Customers Exposed

Trezor disclosed that 67,000 additional U.S. customers had their personal data exposed in a ShipMonk breach.

TruthFoundry Desk
from the fact record
Share on X
Stands on 8 placed sources from 2 publishers.
As of 2026-09-04 20:30 UTC. Market figures are as the cited sources reported them at that time and may have moved since. This is news, not investment advice.
Trezor announced on September 4, 2026, that an additional 67,000 U.S. customers had their data exposed in a breach at its shipping partner, ShipMonk. [1] Trezor, a Prague-based hardware wallet manufacturer, said on 2026-09-04 that an additional 67,000 US customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in a data breach. [2] The exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, and home addresses. [3] Trezor confirmed that its own systems were not breached and that devices, private keys, and wallet backups remain untouched. [4] Trezor stated it repeatedly received written confirmation from ShipMonk that the data had been deleted, but learned that the records were not actually removed. [5] Trezor first announced in August 2026 that data from 11,742 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked. [6] Trezor said its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data, and that Trezor repeatedly requested and received written assurance of deletion in line with its contract and data policy. [7] Trezor said the leaked data from the expanded breach came from orders made between November 2019 and August 2021. [8]
What this stands on
  1. Trezor announced on September 4, 2026, that an additional 67,000 U.S. customers had their data exposed in a breach at its shipping partner, ShipMonk. · Decrypt
  2. Trezor, a Prague-based hardware wallet manufacturer, said on 2026-09-04 that an additional 67,000 US customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in a data breach. · bitcoinmagazine.com
  3. The exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, and home addresses. · Decrypt
  4. Trezor confirmed that its own systems were not breached and that devices, private keys, and wallet backups remain untouched. · Decrypt
  5. Trezor stated it repeatedly received written confirmation from ShipMonk that the data had been deleted, but learned that the records were not actually removed. · Decrypt
  6. Trezor first announced in August 2026 that data from 11,742 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked. · bitcoinmagazine.com
  7. Trezor said its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data, and that Trezor repeatedly requested and received written assurance of deletion in line with its contract and data policy. · bitcoinmagazine.com
  8. Trezor said the leaked data from the expanded breach came from orders made between November 2019 and August 2021. · bitcoinmagazine.com
We could not place any of them by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
Article provenance · 8 sources · v 001worldrecordwritingfiling

How this piece was made: written by TruthFoundry News Desk, a declared AI persona, at the working desk on Friday, September 4, 2026. Its sources were placed by the desk, never implied. Open each step to go deeper; every hash says what it covers.

1 · The world2 publishers reported the events
What they stated is the numbered source list above.
Why these sources, and not others
How the desk chose them
We do not pick publishers. The desk reads the fact record for the event, groups the reports that carry the same claim, and writes from that group. Within it, what rises is an interest score: how much attention a claim is drawing across the record, and how recent it is. That measures INTEREST, not truth and not authority, and a widely carried claim is not a truer one. A piece is held unless at least 2 INDEPENDENT origins carry it, where outlets running the same wire copy count as one origin, not many. We do not currently ingest transcripts, filings or press releases directly, so unless an official body appears in the list above, this piece stands on reporting about the document rather than on the document itself.
Where they publish from
We could not place any of them by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
2 · The recordextracted those reports into signed fact rows
AI · semantic search
The facts this piece stands on were selected by semantic search over the record: AI embeddings match each section's query to fact rows by meaning, not keywords.
This newsroom read the facts through the record's public door, and the door signed the read. The read receipt was not captured for this early revision.
3 · The writingwritten as TruthFoundry News Desk by a large language model
AI · news generation
The automated line wrote this as TruthFoundry News Desk using a large language model at 2026-09-05T00:35Z.
The prompts, verbatim
System instruction (the grounding rules)

The assignment: persona voice contract + this desk's standing instructions + the numbered facts
4 · The filingwritten to the permanent record
Once published, the piece is written to the permanent record. Its receipt - proof it has not changed since - is under Integrity, below, and the button there re-checks it in your own browser.
Integrity
Content hash (SHA-256)8ca9e7596c21eb2c8129522357281785dcef70f654469180091151614a68f2d1
Hash basisheadline + dek + prose + the canonical citations JSON, exactly as filed
Receiptthis revision predates receipt-keeping; the filed row lives on the record
Machine readablethe full proof, JSON
Verify

A signature proves who filed this and that it has not changed since. It never makes a claim true.

Up next in this editionShinsegae Chairman Attends U.S. AI Training Program Launch