Trezor Data Breach Exposes Details Of 13,689 Customers

Bybit
Ledger


What to know:

  • Trezor says data from 13,689 customers was exposed through shipping partner ShipMonk.
  • Trezor says wallets, private keys, and recovery backups remained safe during the breach.
  • Leaked contact details create major phishing, impersonation, and physical security risks.

The Trezor data breach exposed personal information belonging to 13,689 customers through shipping partner ShipMonk. Trezor disclosed the incident on Thursday. It said its wallets, private keys, backups, and systems remained secure during the intrusion.

ShipMonk notified Trezor on August 10 after finding unauthorized access to systems holding order records. The Trezor data breach covered purchases made from May 10 through August 8. Those orders went to customers in seven countries.

Also Read: Metaplanet BTC Holdings Remain at 43,000 BTC After Large Transfer

Phemex

What Was Exposed in the Trezor Data Breach?

The intruder stole names, phone numbers, email addresses, and shipping addresses for 11,742 buyers. Moreover, another 1,947 customers were left with stolen names, cities, and email addresses. The shipments went to the USA, the UK, Sweden, Colombia, Brazil, Italy, and Portugal.

According to Trezor, the breach occurred within ShipMonk’s domain and was never able to affect its systems. No hardware wallets, private keys, or wallet recovery were compromised in the Trezor data breach.

Trezor described fraud as the most imminent threat facing the customers. This could be achieved through the impersonation of the company, the bank, or the exchange using emails, phone calls, and physical mail. 

In this case, they may then demand urgent action or request sensitive wallet information.

Customers were told to scrutinize any email that came and validate the claims. Trezor advised users not to enter their wallet backup on any website. The company informed all customers who were affected by the Trezor data breach.

Why the ShipMonk Leak Raises Wider Safety Concerns

A 90-day deletion rule for fulfillment partners kept older order information beyond the intruder’s reach. Trezor said customers without a notification email were not included in the leak. Trezor and ShipMonk continue to investigate how the access occurred.

In 2020, Ledger experienced a larger client leak. Details linked to about 272,000 individuals were published subsequently. Some customers received email ransom demands after their names, addresses, and phone numbers were disclosed.

Physical attacks against cryptocurrency owners have also increased. CertiK confirmed 52 cases in the first half of 2026, up from 39 one year prior. According to Chainalysis, more than $30 million worth of cryptocurrency has been stolen via physical thefts.

The latest Trezor data breach reveals phone numbers and shipping addresses. Trezor has operated since 2013, though a third-party support portal was compromised in 2024. 

In that case, the leak revealed names and email addresses for about 66,000 users, although the company said no client funds were lost.

How Trezor Plans to Strengthen Customer Privacy

The disclosure also comes amid fallout from a Coldcard firmware vulnerability. Casa said that the issue preceded movements of nearly 233,000 Bitcoins from long-held wallets. A number of Trezor and Ledger holders had migrated their funds to multisig.

Trezor warned the buyers to use anonymous emails, make payments with cryptocurrency, or select post office boxes. 

Anonymous Delivery with neutral packaging and locker delivery across Europe will be available as of September 2026. The service’s roll out in the USA by year-end is planned while the Trezor data leak investigation is ongoing.

Also Read: Crypto Whale Wallet Loses $25.6M in Another Major Phishing Attack



Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*