Skip to main content

Trezor Confirms Data Breach Impacts 67K More U.S. Customers



Trezor says the fallout from a data breach linked to its fulfillment processes is wider than it previously estimated. In an updated message posted to X on Friday, the hardware wallet provider reported that an additional 67,000 US customers may have had their full order details exposed after a shipping partner allegedly failed to delete data tied to specific orders.


Trezor emphasized that its own systems were not compromised. Instead, it pointed to third-party handling of order information, warning that the exposed details could still create risk for users—primarily through phishing and social engineering attacks aimed at stealing seed phrases.



Key takeaways



  • Trezor reports that the affected group now includes an additional 67,000 US customers, expanding beyond the earlier estimate.

  • The company says its hardware wallet systems were not breached, but order data may have remained accessible through a shipping provider.

  • Exposed details include names, emails, shipping addresses, and order information—data that can help scammers craft convincing impersonation scams.

  • Trezor warns the most serious risk is attackers using phishing to trick users into revealing seed phrases.



What Trezor says was exposed—and who is potentially at risk


According to the update posted by Trezor on X, the expanded estimate is connected to new information from its shipping provider, ShipMonk. Trezor said the breach may endanger users who placed orders between November 2019 and August 2021, a timeframe tied to those orders being potentially associated with accessible records.


In Trezor’s account, the exposed information would include full customer details such as a user’s name and email address, the shipping address used for the order, and order specifics. While that does not, by itself, grant access to a wallet, it can substantially lower the effort required for scammers to appear legitimate.


Trezor also indicated that these users had “full details exposed,” and it placed responsibility on ShipMonk for allegedly not deleting the order data from those records. The company said it had received written assurances from ShipMonk, according to the Friday update.



Why order-data breaches matter for hardware wallets


Hardware wallet security is designed to protect seed phrases and private keys from direct compromise. However, phishing is a different threat model: attackers do not need to break cryptography if they can trick users into voluntarily handing over the recovery information.


Trezor’s warning centers on that impersonation angle. With personal and order information in hand, attackers can send more targeted messages pretending to be Trezor support or other legitimate channels. If users follow the instructions in those messages, attackers could attempt to obtain seed phrases—the core secret that controls access to funds stored on a wallet.


Even if the breach did not expose wallet credentials directly, the disclosed details can make scams more believable, increasing the likelihood that some recipients will engage with fraudulent prompts.



How the estimate evolved over time


The updated number represents a clear change from earlier reporting. In August, Trezor initially estimated that about 14,000 users had their data exposed through ShipMonk, according to earlier coverage from Cointelegraph. Later, in January 2024, Trezor reported that roughly 66,000 users were at risk of phishing attacks if they contacted the company’s support team after December 2021.


By contrast, the new update on Friday frames the exposure in terms of a larger pool of US customers—those who ordered between November 2019 and August 2021—and it describes the data as fully detailed, rather than limited to a narrower set of circumstances.


This progression matters because it shifts the practical risk assessment for users. Instead of viewing the incident as affecting a small group—or as primarily tied to interactions with support—Trezor is now indicating that a much wider set of customers may have had sufficient personal and purchase context to support highly targeted phishing attempts.



Impersonation scams remain a major driver of crypto losses


Phishing and social engineering have repeatedly been shown to succeed without exploiting software vulnerabilities—largely because they rely on human trust and urgency. That dynamic has been reflected in security reporting for the broader crypto sector.


According to Hacken’s reporting cited in earlier Cointelegraph coverage, phishing attacks and social engineering accounted for $306 million of the $482 million lost in the first quarter of the year—making up the majority of industry losses during that period. The figure underscores that even when systems remain secure, compromised or leaked personal data can still fuel harmful scams.


Real-world examples also illustrate how convincing these approaches can be. Earlier coverage from Cointelegraph described a case in which a crypto investor lost nearly $1 million after signing a malicious token-approval phishing transaction on Ethereum.



What users should watch for next


With Trezor warning that attackers may use the exposed order details to impersonate the company, users in the affected period should remain alert for unsolicited messages that reference their purchase, ask for recovery information, or direct them to “support” pages. The immediate uncertainty is how many scam attempts will follow—but the underlying threat model (phishing toward seed phrases) is already clear from Trezor’s own assessment.



https://www.cryptobreaking.com/trezor-confirms-data-breach-impacts/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Trezor%20Confirms%20Data%20Breach%20Impacts%2067K%20More%20U.S.%20Customers%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

XRP vs. SOL: Massive Market Interest Gap Revealed by Exec

Here's the revised article with an introduction, key takeaways, and optimized for readability, SEO, and journalistic integrity while preserving the original HTML structure: --- As the crypto market continues to evolve, investor preferences remain primarily anchored around Bitcoin and Ethereum, with questions surrounding the next wave of promising digital assets. Recent insights from Coinbase Asset Management highlight the current sentiment and potential candidates vying for a top position in the rapidly expanding blockchain ecosystem. From institutional interest to network development, the race is on to identify the next asset that could join the ranks of dominant cryptocurrencies like Bitcoin and Ethereum. Investors predominantly view Bitcoin and Ethereum as the primary crypto assets for portfolio inclusion. Solana is seen as a tentative third choice, with XRP potentially vying for the next spot pending network growth. Ripple’s XRP is making strides, but market con...