
AI-generated summary
Trezor initially disclosed a data breach on August 13 affecting 13,689 customers, attributing it to a vulnerability in ShipMonk's systems. The company stated that older order data had been deleted per its 90-day policy, but a September 4 update revealed that data from 2019 to 2021 remained in ShipMonk's systems despite written deletion assurances.
Hardware wallet maker Trezor says a breach at logistics provider ShipMonk exposed contact and order data for another approximately 67,000 U.S. customers after years-old records remained in the vendor's systems despite written deletion assurances.
The Sept. 4 update expands an incident Trezor initially said affected 13,689 people. The two disclosed groups imply a total of roughly 80,689, although Trezor has not issued a single combined figure or published underlying data showing whether the groups overlap. Its use of “another” indicates that it considers the new records additional to the original cohort.
The newly disclosed records cover U.S. orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. The data can connect an identifiable person and physical location with a hardware-wallet purchase, creating risks beyond a conventional email leak.
Old data outlived a 90-day policy
When Trezor first disclosed the breach on Aug. 13, it counted 11,742 customers with full exposure and 1,947 with partial exposure. Trezor's Aug. 13 account said older order data had already been deleted. An Aug. 14 clarification acknowledged that some partially exposed records included older orders.
The Sept. 4 update reverses that understanding. Trezor said it repeatedly requested and received written assurances that ShipMonk had deleted the data, yet records from 2019 to 2021 remained. Trezor's published delivery-data policy says customer details should be deleted from both its own and its fulfillment partner's systems after 90 days, with exceptions for ongoing order issues. The assurance letters and their dates have not been made public.
BleepingComputer reported that a ShipMonk notification attributed the original unauthorized access to a vulnerability in analytics platform Metabase. Metabase said the August zero-day could create a session tied to an administrator account and allow bulk table downloads. Once the provider incident was reassessed, the retained historical data expanded the number of Trezor customers known to be exposed.
The breach did not reach Trezor's wallet systems. The company said its systems, products and services were not compromised and its devices remained secure. The listed exposed fields were contact and order data, not recovery seeds, private keys or wallet funds.
The risk instead sits around the wallet. Trezor warned that the information could support convincing scam emails, fraudulent calls or letters and potential physical targeting. Its Sept. 4 update did not identify a confirmed downstream attack caused by this dataset, so those outcomes remain risks rather than documented consequences.
Trezor said it emailed every newly affected customer directly and that anyone who did not receive its incident notice was not affected. It urged customers never to share a wallet backup or enter it on a website.
For hardware-wallet owners, the episode shows that protecting keys does not erase the purchase trail created by fulfillment. A deletion policy offers little protection if a vendor's compliance is not verified.
AI outlook — possibilities, not facts
Trezor will implement stricter vendor compliance verification for data deletion policies
Likely · Within months
Affected customers may increase use of security measures such as two-factor authentication and phishing awareness
Possible · Within weeks

In July 2024, Compound DAO narrowly passed a controversial proposal to transfer $24 million in COMP tokens to a small group of voters during a last-minute voting surge, exposing how governance mechanisms like registration, staking, and delegation can concentrate power and enable treasury raids even when code functions as intended. Research from Max Planck Institute and Vrije Universiteit Amsterdam found similar vulnerabilities across 48 major Ethereum DAOs, where voting power is often controlled by a small number of large holders, exchanges, and delegation services, undermining broad participation despite thousands of token holders.

Robinhood Chain, a layer-2 blockchain built on Ethereum via Arbitrum Dedicated Blockchains, launched on mainnet July 1, 2026, enabling tokenized stocks, ETFs, and DeFi applications. It uses ETH as gas, supports EVM compatibility, and has seen rapid growth in transactions, DEX volume, and fees, with notable activity from meme coins like Cash Cat and Pons, and tokenized assets reaching $219.49 million in market cap by September 4, 2026.

Solana's first rent reduction, live since September 3, lowers the SOL required to maintain token accounts, allowing excess SOL to be reclaimed. A full 90% reduction would enable tenfold account growth for the same reserve requirement, though only the initial step is active on mainnet. The change reduces upfront capital for new accounts and lets existing account holders withdraw surplus SOL via authorized transactions.

Google has patched a high-severity Chrome vulnerability (CVE-2026-85046) after discovering attackers were already exploiting it. The type-confusion flaw in the V8 JavaScript engine affects Windows, Mac, and Linux versions. Google awarded a $1,000 bug bounty to researcher Salvatore Gulizia for reporting the issue on August 4, 2025, but has not identified attackers, victims, or the exploit's capabilities.

Anthropic's Claude AI has formally proven Fermat's Last Theorem by generating 13 million lines of machine-verifiable code in 11 days. The project, led by researcher Tianyi Peng, utilized a multi-agent system to verify Andrew Wiles's existing 1995 proof.

Solana's upcoming v1 transaction format increases payload capacity from 1,232 to 4,096 bytes but risks failures in RPC clients, indexers, relayers, and fee sponsors if not updated, with some systems crashing and others running with incorrect resource limits; minimum required upgrades include specific versions of Solana SDKs and tools.