Trezor data breach expands to 67,000 more customers, with exposed records dating back to 2019 despite promised 90-day retention limits.
Regulation & Gov ·
Trezor's hardware wallet customer data exposure has grown substantially. An additional 67,000 U.S. customers were affected by a breach at ShipMonk, Trezor's shipping provider, stemming from orders placed between November 2019 and August 2021. The total number of exposed customers now exceeds 80,000.
The compromised information includes names, email addresses, phone numbers, and shipping addresses for 12,742 individuals. Trezor stated that its own infrastructure remained secure and that the breach originated entirely from ShipMonk's systems. The company has alerted users to risks of targeted scams and physical security threats given the disclosure of their personal and address data.
The scope and timeline of the exposure—spanning nearly two years of historical orders—suggest a prolonged security gap at the third-party provider. The full extent of downstream risks to affected customers, and what remediation measures ShipMonk or Trezor are implementing beyond the disclosure itself, remain unclear.