QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

Trezor data breach reveals expanded customer exposure and security concerns

Trezor’s data breach now affects approximately 80,689 customers, raising serious security and privacy concerns.

06 October 2026 · 4 min read
Trezor data breach reveals expanded customer exposure and chainlink-amid-rising-bridge-security-concerns/">security concerns

In a concerning turn of events, the number of Trezor users affected by a significant data breach has surged to approximately 80,689. The revelations come after it was discovered that supposedly deleted shipping logs were still accessible in the systems of logistics provider ShipMonk. This latest update has resounded throughout the crypto community, raising alarm over the vulnerability of hardware wallet users.

This breach follows a troubling trend of heightened risks for those involved in cryptocurrency transactions. With incidents such as home invasions and phishing attacks on the rise, users are finding that their physical safety may be at risk along with their digital assets.

Understanding the scale of the breach

Initially reported on August 13, the Trezor breach implicated roughly 13,689 customers. However, a recent update from Trezor on September 4 confirmed that an additional approximately 67,000 U.S. customers' data had been compromised, bringing the total figure to around 80,689. Despite these alarming statistics, Trezor has yet to provide a full combined total or confirm any overlapping data from the two groups.

The newly exposed data includes sensitive information collected from U.S. orders made between November 2019 and August 2021. This data contains customer names, email addresses, phone numbers, shipping addresses, and order numbers. Most notably, this information can link customers directly to a specific hardware wallet purchase, amplifying the risks associated with identity theft and physical intrusions.

The initial statement from Trezor did not anticipate this escalation, noting that records older than a specified period should have been deleted as per their data retention policy. This has raised questions about the effectiveness of data management practices within third-party vendors and the implications for customer privacy.

Details surrounding data retention policies

Trezor’s published policy mandates that customer data should be purged from both their own and ShipMonk’s systems after a 90-day period, barring instances of ongoing order inquiries. Despite this, the earlier reports suggested that crucial historical data remained intact at ShipMonk, contradicting the assurances Trezor believed they had received.

An investigation by BleepingComputer has suggested that the breach stemmed from an unauthorized access vulnerability in the analytics platform Metabase, which reportedly allowed attackers to compromise administrative accounts and download extensive tables. This breach made it evident that the data retention issues were not merely theoretical but rooted in significant operational failures within the logistics provider's data management practices.

Furthermore, although Trezor has assured users that their wallet systems were not compromised and that no recovery seeds, private keys, or funds were exposed, the nature of the data leak heightens the risk of social engineering attacks. This means that attackers could exploit the exposed information to craft convincing phishing emails or conduct aggressive scams directly targeting affected customers.

Physical safety risks and customer response

The ramifications of this breach extend beyond the digital world, as hardware wallet users may find themselves at an increased risk of physical threats. Trezor has warned that the details uncovered in this data breach could lead to situations where criminals use the information to locate and target individuals who own significant amounts of cryptocurrency. The appeal of hardware wallets lies in their security; however, this incident underscores a vital point for users: even the most secure digital wallets can have vulnerabilities in the procurement and delivery process.

In light of these events, Trezor has reached out directly to each newly affected customer with notifications of the breach and guidance on maintaining their security. Importantly, the company has emphasized that users should never disclose their wallet backup details or enter them into suspicious websites, reiterating best practices in the crypto ecosystem.

The imperative for improved vendor security measures

This incident reveals a pressing need for hardware wallet companies to scrutinize the compliance standards and security measures of their vendors. While Trezor has taken steps to proactively engage with affected customers, the broader responsibility for safeguarding user data must extend to the partners they rely on for order fulfillment.

Customer confidence hinges not only on the security of the products themselves but also on the integrity of the systems that support their transactions. As this incident demonstrates, the links in the supply chain must be fortified to ensure that customer information remains confidential and secure.

Ultimately, as the crypto landscape continues to evolve, so too must the standards of security and data management practices. The Trezor breach serves as a critical reminder of the vulnerabilities inherent in the intersection of digital currency storage and physical logistics.

As always, regulatory vigilance and proactive measures are essential in protecting consumer interests in the rapidly changing world of cryptocurrency.