Trezor Data Breach Balloons: 67,000 More U.S. Customers Exposed

Isometric data visualization with frosted glass Maker token surrounded by fragmented panels and market candle shadows
David E | ALTCOINS | 5 days ago

Supposedly Purged Logs Return to Haunt Trezor, the Prague-based hardware wallet maker, has revealed that a breach at its logistics partner ShipMonk exposed an additional 67,000 U.S.

Supposedly Purged Logs Return to Haunt

Trezor, the Prague-based hardware wallet maker, has revealed that a breach at its logistics partner ShipMonk exposed an additional 67,000 U.S.

This marks a dramatic escalation from Trezor’s August announcement, when the company said just under 12,000 customers across seven countries—including the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal—had been affected. The latest update means the pool of exposed individuals has grown by more than six times for U.S. customers alone.

ShipMonk’s Promise Broken, Data Lingers

The breach traces back to ShipMonk’s failure to erase years-old customer data despite providing Trezor with written assurances that all records had been deleted. According to bitcoinmagazine.com, Trezor had relied on these assurances as part of its own delivery-data policy, which mandates deletion of customer details from both its and its partners’ systems after 90 days unless there are ongoing order issues.

Instead, logs from as far back as late 2019 remained in ShipMonk’s systems and were subsequently accessed through an unrelated vulnerability in analytics platform Metabase.

This tension—between what Trezor believed was secure and what was actually happening at its fulfillment partner—has left tens of thousands more customers at risk. Notably, this is the first time since Trezor’s founding in 2013 that such a wide array of personal information including phone numbers and shipping addresses has been exposed in a single incident.

Sixfold Jump in Exposed Users

Trezor’s September 4 update revised the number of people affected from an initial tally of 13,689 to roughly 80,689—though it remains uncertain whether some users appear in both groups or if these are entirely separate cohorts. The newly disclosed batch specifically involves U.S. orders placed over a span of nearly two years.

While the breach did not compromise Trezor’s wallet systems or any cryptographic secrets such as recovery seeds or private keys, it did expose enough personal data to potentially enable phishing attacks or identity theft schemes targeting crypto holders. In January 2024, a separate incident had already put about 66,000 Trezor support desk users at risk of phishing attempts after their contact information was leaked.

Why It Matters: Practical Impact for Crypto Users

For users who purchased hardware wallets between November 2019 and August 2021—or those who have contacted Trezor support since December 2021—the practical implications are significant. Leaked names, emails, phone numbers, and shipping addresses can be weaponized for convincing phishing attempts or even physical threats. While no funds or wallet credentials were directly compromised by this breach, attackers often use such personal data to trick victims into revealing passwords or recovery phrases through fake emails or calls.

Trezor responded by emailing every impacted customer directly; anyone who did not receive a notice is reportedly unaffected. Still, the scale and duration of this exposure highlight the limits of relying solely on third-party assurances for data security—a lesson likely to reverberate across the crypto industry given the growing reliance on external logistics providers.

Policy vs. Practice: Data Retention Gap

Trezor’s published delivery-data retention policy states that customer details should be purged from all systems within three months unless there are unresolved order issues. Yet this incident demonstrates how gaps between written policies and actual practices can persist undetected for years—ShipMonk kept logs for nearly two years beyond their supposed deletion date before they were discovered in connection with this breach.

The headline number—67,000 additional U.S. customers exposed—is stark; however, the context is messier: Trezor had received repeated written confirmations from ShipMonk about deletion but lacked direct oversight into enforcement. This disconnect underscores how even robust internal protocols can be undermined by lapses at external vendors.

The Summary

  • On September 4, Trezor revealed that 67,000 more U.S. customers were affected by the ShipMonk data breach.
  • The exposed data covers orders from November 2019 to August 2021 and includes names, emails, phone numbers, and addresses.
  • Trezor's wallet systems, private keys, and funds were not compromised in this incident.

Key variables ahead

If Trezor confirms whether the newly disclosed 67,000 U.S. customer records overlap with the previously reported 13,689 affected individuals—a detail not yet clarified as of the September 4 update—the immediate total number of unique customers exposed in the breach could change substantially.

React to this article

About the Author

David E

David E

Writer – DeFi & crypto markets

With a keen interest in decentralized finance and digital asset markets, David closely monitors Layer 1 and Layer 2 protocol developments. His articles break down market movements, token launches and governance issues shaping today's crypto landscape.