Trezor: Data of 67,000 additional customers exposed
Summarize this article with:

New data leak widens incident affecting hardware wallet buyers. Trezor says the information of an additional 67,000 U.S. customers was exposed after a breach at its logistics partner Shipmonk. The affected files should have disappeared from the provider’s systems, but they remained accessible. The affected orders date from November 2019 to August 2021. With the 13,689 customers identified, the incident affects approximately 80,000 people, without compromising wallets, private keys or backups.

Illustration of a Trezor data leak showing 67,000 US customers exposed and personal information scattered around a secure wallet.

In brief

  • 67,000 additional US customers affected by Shipmonk data breach.
  • The incident now affects approximately 80,000 customers, with no compromise of private keys or recovery phrases.
  • Exposed data includes names, emails, telephones, delivery addresses and order numbers.
  • Trezor is preparing anonymous delivery to Europe from September, then to the United States before the end of 2026.

Trezor discovers 67,000 new affected US customers

The hardware wallet company learned on September 2 that theincident at Shipmonk exceeded initial estimates. The new records relate to U.S. buyers who ordered between November 2019 and August 2021. The exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers. This information can help scammers construct credible messages.

According to Trezor, she had repeatedly asked Shipmonk to delete this information. The service provider had confirmed their deletion in writing. The company indicates that this procedure also corresponded to its data policy. The discovery of old files therefore calls into question the real application of these commitments.

This situation also raises questions about the retention of data for 90 days announced to logistics partners. The recordings concerned remained stored for several years, while the American orders date back to 2019. The duration observed far exceeds the announced deadline. The case above all highlights the importance of controlling information entrusted to external service providers.

Start your crypto adventure with Kraken
This link uses an affiliate program

A leak that widens the risks for customers

The leak does not give attackers direct access to customer wallets. Private keys and recovery phrases remain beyond the reach of this intrusion. These elements control the cryptocurrencies held in a wallet. Trezor therefore clarifies that the incident concerns personal and commercial data, not the mechanisms for moving assets.

However, the information revealed creates other risks for those involved. A phone number or home address can facilitate more targeted scam attempts. Order numbers can also help a fraudster replicate real details when contacting a victim. This data can make a spoof more convincing.

Trezor reiterates that no member of its team will request a wallet backup. Customers should never enter their recovery phrase on a website. They should also not pass it on to anyone claiming to provide assistance. This instruction becomes important when personal data reinforces a fraudulent approach.

A flaw located at the logistics provider

The origin of the incident lies outside Trezor’s systems. Attackers exploited a previously unknown SQL injection vulnerability in Metabase, an analytics platform used by Shipmonk. The breach allowed access to the service provider’s data. Metabase notified Shipmonk around August 6, then fixed the vulnerability and invalidated the sessions.

Shipmonk later said it secured its systems after discovering the vulnerability. The incident shows that security also depends on the services used during an order. Delivery data may remain exposed despite wallet integrity. This distinction separates asset security and personal information.

The case comes after other incidents. A leak that occurred in 2022 had reached approximately 106,856 customers. In 2024, the compromise of a support portal had exposed up to 66,000 names and email addresses. In both these precedents and the current incident, hardware wallets were not remotely compromised.

Trezor prepares more discreet delivery

Faced with the risks associated with orders, Trezor highlights an anonymous delivery system. The goal is to reduce the amount of data retained during the purchase of a hardware wallet. The system provides collection at a relay point, neutral packaging and a generic sender. It also provides for the automatic deletion of identifiers after delivery.

Trezor plans a European launch in September, then a deployment in the United States by the end of 2026. This device should reduce the circulation of logistics data. The company therefore seeks to limit the information available after delivery. This development comes as the number of people affected approaches 80,000.

For the moment, Trezor has not announced a withdrawal from its partnership with Shipmonk. She had indicated that she would decide on the future of this relationship after evaluating the incident. The question remains open as new data expands the scope of the leak. What happens next will depend on the measures taken to retain and protect customer data.

The incident ultimately shows that the protection of a hardware wallet is not limited to its private keys. Purchasing and delivery information may also become a target for a third-party provider. With this assessment, Trezor must deal with a wider exposed perimeter, while anonymous delivery must gradually come into service in the coming months.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts