Search the site
Press ESC to close
LIVE
Loading...
Updating...

Trezor Data Breach Escalates: 67,000 US Customer Records Exposed

Dmitri Shakhov
Fact-checked
2 min read
385 words
Share

The hardware wallet manufacturer Trezor has confirmed a significant expansion in the scope of a previously identified data breach. Recent investigations reveal that an additional 67,000 customers located in the United States have had their personal information compromised. The leak originated from a security incident at ShipMonk, a third-party logistics provider used by the company to handle product distributions. This development marks a serious update for users who interacted with the brand over a two-year period, highlighting the persistent risks associated with third-party supply chain vulnerabilities in the cryptocurrency sector.

Scope of the Compromised Data

The breach specifically impacts individuals who placed orders for Trezor hardware wallets between November 2019 and August 2021. According to the official announcement, the exposed data is comprehensive and includes sensitive identifiers that could be used in targeted attacks.

  • Names and email addresses
  • Phone numbers
  • Physical shipping addresses
  • Order identification numbers

Trezor has clarified that its internal systems and hardware devices remain secure and were not directly accessed during this incident. The compromise occurred exclusively within the databases of the logistics partner. The company has already dispatched notification emails to all affected parties; users who have not received such communication are currently deemed unaffected by this specific leak.

Security Recommendations and Future Mitigation

While the private keys and digital assets stored on the wallets are not at risk from this breach, the exposure of physical addresses and contact details introduces secondary threats. Trezor has urged its community to remain hyper-vigilant against sophisticated phishing campaigns, fraudulent phone calls, and potential physical security risks.

We are accelerating the launch of an anonymous shipping option to reduce future privacy exposure and ensure that the amount of sensitive data held by third-party partners is minimized.

To prevent similar occurrences, the firm is transitioning toward more private delivery methods. This move aligns with a broader industry trend where blockchain security firms are seeking to decouple personal identity from hardware ownership to protect users from "wrench attacks" and digital social engineering.

The incident serves as a reminder that even when cold storage technology is robust, the metadata surrounding the purchase of such devices remains a high-value target for malicious actors. US-based users are advised to monitor their communication channels closely and treat any unsolicited requests for sensitive information with extreme skepticism.

Frequently Asked Questions

Quick answers to the most common questions about this topic.