Trezor Data Breach Tops 80,000 Customers After Old Records Surface

Alexey Bondarev
Alexey Bondarevpage_time_minutesAgo
Customer data exposure at Trezor’s shipping partner now affects more than 80,000 users (Image: Shutterstock)
Customer data exposure at Trezor’s shipping partner now affects more than 80,000 users (Image: Shutterstock)

Trezor says 67,000 more U.S. customers were exposed in a breach at its shipping provider, pushing the known affected total above 80,000.

Key Points:

  • 67,000 additional U.S. customers had full order information exposed, lifting the known total above 80,000.
  • The newly identified records date from November 2019 through August 2021.
  • Trezor says its systems, devices, private keys and wallet backups were not compromised.

Trezor Breach Expands

In a Sept. 4 update, Trezor said another 67,000 U.S. customers were affected, with records tied to orders placed between November 2019 and August 2021.

The exposure included names, email addresses, phone numbers, shipping addresses and order numbers. All newly affected customers have been notified by email.

ShipMonk, Trezor's logistics provider, had kept those records even though Trezor said it repeatedly requested deletion and received written assurances that the data had been removed under its contract and data policy. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said.

That takes the known total above 80,000. Trezor's August notice said 11,742 customers had names, emails, phone numbers and shipping addresses exposed, while 1,947 had more limited information compromised.

Also Read: Bitcoin Posts Best Month Since 2024, Yet Fidelity Won’t Call The Bottom

Crypto Security Risk

Trezor said its own systems were not breached, and the incident did not expose private keys, wallet backups or device secrets. The company said its hardware wallets remain secure.

The main risk is the leaked customer data, which can help attackers identify hardware wallet owners and tailor scams around information that appears legitimate.

Trezor warned affected users to expect fake emails, fraudulent calls and physical letters, and it also highlighted possible physical-security threats. That makes the exposure more than a conventional account-security problem.

Security firm TRM Labs has argued that self-custody does not eliminate risk, but shifts it to different parts of the security chain. In this case, the wallet itself may remain protected while shipping records expose the owner’s identity, contact details and home address.

The incident was first disclosed Aug. 13, when Trezor said ShipMonk's breach affected about 13,689 customers and initially tied most exposure to recent orders under a 90-day retention policy.

The later discovery of records dating back to 2019 shows older customer data remained in ShipMonk's systems despite Trezor's deletion requirements.

Read Next: iPhone Ultra May Land At $2,550 Average, Helping Apple Redraw Foldable Market

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer
page_blogs_view_latest
Show All News
Trezor Data Breach Tops 80,000 Customers After Old Records Surface | Yellow