NewsCryptoTrezor Data Breach Grows to 81,000 Affected Customers, Including 67,000 in the U.S.

Trezor Data Breach Grows to 81,000 Affected Customers, Including 67,000 in the U.S.

Author: Hokanews·

Key Takeaways

  • The number of Trezor customers potentially affected by the data breach has increased from the initially reported 13,689 to roughly 81,000.
  • Approximately 67,000 U.S. customers reportedly had names, phone numbers, and shipping addresses exposed in the breach.
  • The breach involved data managed by third-party fulfillment company ShipMonk, which had repeatedly confirmed the data was deleted even though it had not been removed.
  • No cryptocurrency wallet recovery credentials were directly exposed; the compromised information is limited to personal details.
  • Trezor has directly contacted affected customers and warned them about potential physical security threats arising from exposed addresses and contact information.
Trezor Data Breach Grows to 81,000 Affected Customers, Including 67,000 in the U.S.

A data breach at hardware wallet manufacturer Trezor has affected far more customers than initially disclosed, with the number of potentially impacted users rising to roughly 81,000, up from the originally reported 13,689, according to information shared by The Crypto Times on X.

Trezor, owned by Prague-based SatoshiLabs, is one of the longest-established hardware wallet makers, selling devices that store users' private keys offline. That customer base is precisely what makes the breach sensitive: its records identify people who likely hold cryptocurrency, turning an ordinary data leak into a targeted physical-security concern.

The expanded disclosure includes approximately 67,000 customers in the United States whose names, phone numbers, and shipping addresses were reportedly exposed. The scale of the leak has raised concerns that extend beyond digital account security, prompting Trezor to warn affected customers about potential physical security risks.

Breach Scope Expands Significantly

The latest figures mark a substantial increase from the 13,689 customers initially identified as affected. The revised total indicates the incident involved a considerably broader set of customer information than first understood.

According to The Crypto Times, Trezor said the exposed information linked to U.S. customers included names, telephone numbers, and shipping addresses. Such details can reveal where customers live or receive shipments, creating risks that go beyond the compromise of personal data itself.

Trezor has reportedly contacted affected customers directly as part of its response and warned them to remain alert to potential physical security threats.

ShipMonk Data Deletion Under Scrutiny

The incident also centers on data previously handled by ShipMonk, a third-party fulfillment company that managed order shipments and associated customer information for Trezor. Trezor said ShipMonk had repeatedly confirmed that the relevant customer data had been deleted. However, Trezor later determined that the information had not in fact been removed.

The discrepancy between ShipMonk's deletion confirmations and the subsequent discovery of retained data is a key element of the breach, and it helps explain why the scope of affected customers has expanded well beyond the original figure. It also illustrates a broader challenge in supply-chain data governance: companies remain accountable for customer data held by vendors, even when those vendors report the data has been purged. Verifying deletion — rather than relying on vendor attestations — has become a recurring pain point across industries that outsource logistics and e-commerce operations.

According to the information provided by The Crypto Times, the reported exposure involves personal information rather than a direct disclosure of cryptocurrency wallet recovery credentials. Trezor's warning nonetheless underscores why compromised customer records can present risks even when sensitive wallet credentials are not involved: knowing that a household owns a hardware wallet is itself information that bad actors could seek to exploit through social engineering or in-person approaches.

Trezor Warns Customers About Physical Security Risks

Trezor's response has focused not only on protecting affected customers' information but also on the possibility of physical security threats arising from exposed addresses and contact details.

Customers whose names, phone numbers, and shipping information were disclosed could potentially become targets of unwanted contact or attempts to exploit knowledge of their association with a hardware wallet provider. Trezor has therefore urged affected users to take the physical-security implications seriously.

The company says it has contacted customers affected by the incident directly. The increase in the reported number of impacted users means those notifications now apply to a much larger group than initially disclosed.

The latest figures reported by The Crypto Times put the total number of affected customers at around 81,000, while 67,000 U.S. customers were reportedly among those whose names, phone numbers, and shipping addresses were exposed.

Source: Hokanews