
On Tuesday, September 8, 2026, Cybernews reported that cryptocurrency hardware wallet manufacturers Trezor and Ledger are facing significant data breach fallout and legal challenges.
Trezor disclosed that approximately 81,000 of its customers were affected by a personal data leak, a figure nearly six times larger than initially estimated. This breach was attributed to Trezor’s shipping provider, ShipMonk, which also exposed data for an additional 67,000 U.S. clients who purchased hardware wallets between November 2019 and August 2021. The compromised customer data includes full names, shipping addresses, phone numbers, and email addresses.
The initial breach, reported in August of this year, was believed to have affected about 14,000 customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026. Trezor stated that despite receiving written assurances from ShipMonk confirming data deletion in line with their contract and data policy, the information was not removed from their systems. Trezor has urged its customers to remain vigilant against phishing attempts, fraudulent communications, and potential physical security risks.
In parallel, Ledger is confronting a class-action lawsuit stemming from a 2023 data breach. According to Ariel Givner, a fintech counsel, the lawsuit alleges that Ledger downplayed the breach and failed to disclose it in a timely and complete manner.
The complaint further characterizes Ledger’s actions as demonstrating a pattern of negligent, reckless, and irresponsible behavior regarding its security and customer privacy obligations.
The 2023 exploit reportedly led to a small number of users signing transactions that drained their accounts. This legal action follows a history of Ledger experiencing two personal data leaks related to third-party incidents. Furthermore, in 2020, a separate Shopify breach impacted 292,000 Ledger customers.
Source: Cybernews





Be the first to comment