EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The Trezor data breach affected another 67,000 users, totaling more than 80,000

2026-09-05 00:11:59
Bookmark

The impact of Trezor's data breach has expanded to more than 80,000 users.

Following the first disclosure, Trezor issued another statement confirming that the personal information of about 67,000 U.S. customers was exposed due to the data breach of its partner ShipMonk. The time span of new orders from affected customers is from November 2019 to August 2021. Although logistics provider ShipMonk had written confirmation that such data had been completely deleted, this was not the case. Currently, this incident has put the privacy of more than 80,000 users around the world at risk.

Data breach details and timeline

Trezor officials said they deeply regret to inform users that recent updates showed that the number of customers affected far exceeded initial expectations. Specifically, information on another 67,000 U.S. customers who placed orders between November 2019 and August 2021 was leaked. The records were originally thought to have been erased from ShipMonk's systems years ago, based on written guarantees the company had previously provided on request.

According to the disclosed timetable:

  • Phase 1 (disclosed on August 13): involves a total of 13,689 customers who placed orders within the 90 days before August 8, 2026, distributed in seven countries. Among them, complete records of 11,742 people and the names, cities and mailboxes of 1,947 people were leaked.
  • Phase 2 (disclosed on September 4): involves approximately 67,000 customers who placed orders in the United States between November 2019 and August 2021. The leaked fields include name, email, phone number, shipping address and order number.

Trezor emphasized that its 90-day data retention policy was the basis for this initial disclosure. However, ShipMonk violated its contractual commitments and failed to delete old data within the stipulated period, resulting in five years of U.S. order data remaining on the supplier's servers until the platform was attacked. In his public response, Trezor clearly pointed out ShipMonk's responsibility for failing to fulfill its data deletion obligations, which is rare in the cryptocurrency industry, where companies often choose to silently bear reputation damage rather than publicly accuse suppliers.

Security Core is not compromised: Private keys and recovery seeds are absolutely safe

Trezor reiterated that its hardware devices, firmware, and mnemonic (recovery seed) generation process were completely unaffected. At any stage, an attacker cannot access the user's private key or the recovery seed. The breach occurred at a commercial operational level far from hardware security, the infrastructure that supports the logistics of physical products.

Security researchers point out that ShipMonk's intrusion was caused by ransomware group ShinyHunters exploiting an unpatched SQL injection vulnerability in Metabase, the business intelligence software used internally by ShipMonk. Since the vulnerability is a zero-day vulnerability, there was no fix when the attack occurred. This attack takes advantage of flaws in database query execution to obtain sensitive data.

Why is the shipping address more dangerous than the mailbox

An attacker with this dataset would be able to know exactly who purchased the hardware wallet, when it was purchased, and where it lives. This precise combination of information allows fraudsters to send seemingly authentic emails, phone calls or letters quoting real order numbers, thereby inducing victims to reveal key recovery seed phrases.

A similar situation has occurred with Ledger users. In 2020, Ledger leaked the names, email addresses, phone numbers and addresses of more than 270,000 users due to API key vulnerabilities. Subsequently, the victim received fraudulent support calls and fake replacement device emails containing malware. Today, Trezer users face the same potential risk starting point.

Industry Background: Third-party supply chains become a new weakness

During August 2026, there were many security incidents involving third-party suppliers in the cryptocurrency industry:

  • SafePal: Authorization flaws in the third-party order-tracking plug-in resulted in the disclosure of purchase histories, names and email addresses of nearly 39,798 customers, but did not touch wallet infrastructure and funds.
  • BITS of Gold: About 200,000 customer records were leaked at Israel's largest regulated cryptocurrency broker due to a breach of its business communication provider.
  • Coinkite: Similar third-party security issues have arisen during the same period.

According to CertiK statistics, physical and network targeted attacks against cryptocurrency holders increased by 33% in the first half of 2026. It is worth noting that none of these leaks involved a breakthrough at the firmware or cryptographic level. When attackers cannot directly breach secure elements, they instead commit crimes by purchasing customer lists from logistics service providers.

Future countermeasures: Anonymous delivery solution

To address this issue, Trezor has sent notifications from help@trezor.io to affected customers and is developing an "anonymous delivery" option. The plan aims to strip personal data from the transportation records themselves, moving the defense line forward: no longer relying on suppliers to delete data on time, but instead fundamentally avoiding providing such data. Whether this move can be adopted by competitors and whether logistics providers can operate at large scales with minimal identification data will determine whether this is just a feature of Trezor or the default standard across the industry.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP