Trezor's August breach is roughly six times larger than first disclosed, with the hardware-wallet maker saying on Sept. 4 that another approximately 67,000 U.S. customers had contact and order data exposed through its logistics provider ShipMonk. The original Aug. 13 disclosure counted 11,742 customers with full exposure and 1,947 with partial exposure, and the two groups together imply around 80,689 affected people, though Trezor has not published a single combined figure or confirmed whether the cohorts overlap. The newly disclosed records cover U.S. orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers, the kind of identifying detail that links a person to a specific hardware-wallet purchase.
Why it matters
Trezor said its own systems, products and devices remained secure, and the exposed fields are contact and order data rather than recovery seeds, private keys or wallet funds. The risk sits around the user instead. ShipMonk retained historical records well past Trezor's 90-day deletion policy despite repeated written assurances that the data had been purged, and BleepingComputer reported that ShipMonk attributed the underlying unauthorized access to a zero-day vulnerability in the analytics platform Metabase, an exploit that could create an admin-tied session and enable bulk table downloads. Once ShipMonk reassessed the incident, the retained historical data expanded the population of exposed Trezor customers. The episode shows that a vendor-side deletion policy is only as strong as the verification behind it.
Market impact
The dataset can support convincing phishing emails, fraudulent calls and letters, and potential physical targeting, vectors that compound against a backdrop of violent crypto home invasions already documented across the industry. Trezor warned of these outcomes in its Sept. 4 update but did not identify a confirmed downstream attack tied to the dataset, so the consequences remain risks rather than documented results.
Frequently asked questions
-
How many Trezor customers are affected in total?
Trezor's original August disclosure covered 13,689 customers (11,742 fully exposed and 1,947 partially), and the September 4 update added roughly 67,000 more U.S. customers, implying around 80,689 in total, though Trezor has not published a single combined figure.
-
What data was exposed in the Trezor breach?
The exposed records include names, email addresses, phone numbers, shipping addresses and order numbers for U.S. orders placed between November 2019 and August 2021. Recovery seeds, private keys and wallet funds were not affected.
-
Did the breach compromise Trezor wallet devices themselves?
No. Trezor said its own systems, products and services were not compromised and the devices remain secure. The exposure sits in fulfillment-side shipping logs, not on-device wallet material.
-
How did the supposedly deleted shipping logs resurface?
Logistics provider ShipMonk retained historical records well past Trezor's 90-day deletion policy despite written assurances they had been purged. BleepingComputer reported ShipMonk attributed the underlying access to a zero-day in the Metabase analytics platform.
-
What risks do affected Trezor customers face?
The dataset can support convincing phishing emails, fraudulent calls and letters, and potential physical targeting. Trezor urged affected users never to share wallet backups or enter them on websites.
CryptoSlate