Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$79,979▲ 0.51%ETH$2,509▲ 2.30%SOL$104.28▲ 2.36%TOTAL CRYPTO$2.7T▼ 2.26%S&P 5007,718.60▼ 0.23%NASDAQ26,506.99▼ 0.29%DOW53,414.25▼ 1.24%GOLD4,476.60▲ 9.31%WTI91.48▲ 20.73%BRENT96.28▲ 21.32%EUR/USD1.1621▲ 0.99%USD/JPY156.22▼ 0.83%DXY99.16▼ 0.73%

Trezor Breach Widens: 67,000 More US Customers Exposed

Trezor says a breach at shipping partner ShipMonk exposed data of 67,000 more US customers, pushing the total past 80,000 and raising phishing risks.

PartnerSurfshark VPN

Trezor says a breach at its shipping partner ShipMonk exposed personal data of roughly 67,000 additional US customers, pushing the total number of affected buyers past 80,000. The hardware wallet maker disclosed the expanded scope on September 4 after ShipMonk told it two days earlier that the incident covered far more order data than first reported.

The newly identified records date from November 2019 to August 2021, when ShipMonk handled Trezor fulfillment under an earlier arrangement. Exposed details include full names, email addresses, phone numbers, shipping addresses and order numbers. Trezor has emailed all affected customers directly and says anyone who did not get a message from help@trezor.io is not believed to be impacted.

From 14,000 to more than 80,000

Trezor first disclosed the breach on August 13, a few days after ShipMonk reported unauthorized access to its systems on August 10. At that point the company counted 11,742 customers with full exposure to name, email, phone and address, plus 1,947 with partial exposure limited to name, city and email. That came to roughly 14,000 people across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal, and it was already an uncomfortable number for a company whose entire pitch is security.

The September 2 update from ShipMonk changed the picture completely. The logistics firm said the intruder had also reached order records from a previous partnership period, covering orders placed between November 2019 and August 2021. Nearly all of the newly identified victims are in the United States. Trezor published the correction on its blog on September 4 and notified customers by email the same day.

The original figure was held down by a Trezor retention policy that requires fulfillment partners to delete or anonymize order data 90 days after delivery. The newly exposed records predate that policy, which is why they still existed in ShipMonk’s systems years after the orders shipped.

How the breach happened

ShipMonk told affected customers, in notification emails reviewed by BleepingComputer, that attackers exploited a vulnerability in Metabase, a third-party analytics platform it uses. The stolen data sat in a Metabase instance holding Trezor order details. Metabase notified ShipMonk of the unauthorized access on August 6, and ShipMonk passed the information to Trezor four days later.

Trezor stresses that its own infrastructure was not touched. No Trezor system, product or service was affected, and the company says device security is unaffected because hardware wallets never expose keys to a fulfillment partner or any external system. What leaked is metadata about who bought a device and where it was sent, not anything that touches the device itself.

A repeated pattern

The incident is the latest in a string of third-party exposures for the wallet maker. In January 2024 a breach of its support ticketing portal exposed data of 66,000 users who had contacted support since December 2021. In April 2022 attackers compromised an account at email marketing firm Mailchimp and hit 106,856 Trezor customers. Each case followed the same logic: steal real names, emails and order details, then use them to send convincing phishing emails that trick users into entering their recovery seed phrase on a fake site.

A hardware wallet cannot protect a user who voluntarily types a 24-word recovery phrase into a website. The device stays secure; the human is the attack surface. That is why criminals keep buying breach data from wallet companies rather than attacking the devices, which remain practically uncrackable.

Security researchers note that knowing a customer’s physical address is a step beyond email-only leaks. It opens the door to physical threats such as bogus deliveries, impersonation of couriers, or extortion attempts aimed at people assumed to hold crypto. Trezor has not confirmed any exploitation of the leaked data so far, and no fraudulent fund movements have been attributed to this incident.

What customers should do

Trezor’s advice is unchanged: never enter a recovery seed on any website or share it with anyone, verify sender addresses before clicking, and treat any email asking for a seed phrase as an attack regardless of how much order detail it contains. The company notes that attackers with accurate order data can sound more convincing, citing a real order number and shipping date to appear legitimate.

Customers who placed orders with Trezor between November 2019 and August 2021 and now receive an incident notice should assume the notice is genuine, but should still navigate to trezor.io directly rather than through email links. The company says it will not ask for seed phrases under any circumstances.

Wider implications

The breach lands at a busy moment for hardware wallet security. The sector’s user base has grown with the broader market, and phishing operations increasingly draw on real leaked purchase data to target holders with precision. Regulators in Europe and the US have tightened breach notification rules, and supply chain compromises of vendors like ShipMonk sit squarely within the reporting obligations of firms like Trezor even when the compromised system belongs to a partner.

The episode is also a reminder that data minimization policies only work if they apply retroactively across a vendor’s whole history. Trezor’s 90-day deletion rule protected recent orders but did nothing for records accumulated before the rule existed. Buyers of Trezor, Ledger and other devices should expect targeted phishing attempts referencing genuine order details in the months ahead, and should treat unsolicited contact about any wallet purchase as hostile until proven otherwise.

SourcesThe Block; The Hacker News; BleepingComputer; Trezor official blog; Bloomberg.
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch 626 Dormant Bitcoin Wake as $50M Moves Early September Read →