
Trezor says the fallout from a data breach linked to its fulfillment processes is wider than it previously estimated. In an updated message posted to X on Friday, the hardware wallet provider reported that an additional 67,000 US customers may have had their full order details exposed after a shipping partner allegedly failed to delete data tied to specific orders.
Trezor emphasized that its own systems were not compromised. Instead, it pointed to third-party handling of order information, warning that the exposed details could still create risk for users—primarily through phishing and social engineering attacks aimed at stealing seed phrases.
Key takeaways
- Trezor reports that the affected group now includes an additional 67,000 US customers, expanding beyond the earlier estimate.
- The company says its hardware wallet systems were not breached, but order data may have remained accessible through a shipping provider.
- Exposed details include names, emails, shipping addresses, and order information—data that can help scammers craft convincing impersonation scams.
- Trezor warns the most serious risk is attackers using phishing to trick users into revealing seed phrases.
What Trezor says was exposed—and who is potentially at risk
According to the update posted by Trezor on X, the expanded estimate is connected to new information from its shipping provider, ShipMonk. Trezor said the breach may endanger users who placed orders between November 2019 and August 2021, a timeframe tied to those orders being potentially associated with accessible records.
In Trezor’s account, the exposed information would include full customer details such as a user’s name and email address, the shipping address used for the order, and order specifics. While that does not, by itself, grant access to a wallet, it can substantially lower the effort required for scammers to appear legitimate.
Trezor also indicated that these users had “full details exposed,” and it placed responsibility on ShipMonk for allegedly not deleting the order data from those records. The company said it had received written assurances from ShipMonk, according to the Friday update.
Why order-data breaches matter for hardware wallets
Hardware wallet security is designed to protect seed phrases and private keys from direct compromise. However, phishing is a different threat model: attackers do not need to break cryptography if they can trick users into voluntarily handing over the recovery information.
Trezor’s warning centers on that impersonation angle. With personal and order information in hand, attackers can send more targeted messages pretending to be Trezor support or other legitimate channels. If users follow the instructions in those messages, attackers could attempt to obtain seed phrases—the core secret that controls access to funds stored on a wallet.
Even if the breach did not expose wallet credentials directly, the disclosed details can make scams more believable, increasing the likelihood that some recipients will engage with fraudulent prompts.
How the estimate evolved over time
The updated number represents a clear change from earlier reporting. In August, Trezor initially estimated that about 14,000 users had their data exposed through ShipMonk, according to earlier coverage from Cointelegraph. Later, in January 2024, Trezor reported that roughly 66,000 users were at risk of phishing attacks if they contacted the company’s support team after December 2021.
By contrast, the new update on Friday frames the exposure in terms of a larger pool of US customers—those who ordered between November 2019 and August 2021—and it describes the data as fully detailed, rather than limited to a narrower set of circumstances.
This progression matters because it shifts the practical risk assessment for users. Instead of viewing the incident as affecting a small group—or as primarily tied to interactions with support—Trezor is now indicating that a much wider set of customers may have had sufficient personal and purchase context to support highly targeted phishing attempts.
Impersonation scams remain a major driver of crypto losses
Phishing and social engineering have repeatedly been shown to succeed without exploiting software vulnerabilities—largely because they rely on human trust and urgency. That dynamic has been reflected in security reporting for the broader crypto sector.
According to Hacken’s reporting cited in earlier Cointelegraph coverage, phishing attacks and social engineering accounted for $306 million of the $482 million lost in the first quarter of the year—making up the majority of industry losses during that period. The figure underscores that even when systems remain secure, compromised or leaked personal data can still fuel harmful scams.
Real-world examples also illustrate how convincing these approaches can be. Earlier coverage from Cointelegraph described a case in which a crypto investor lost nearly $1 million after signing a malicious token-approval phishing transaction on Ethereum.
What users should watch for next
With Trezor warning that attackers may use the exposed order details to impersonate the company, users in the affected period should remain alert for unsolicited messages that reference their purchase, ask for recovery information, or direct them to “support” pages. The immediate uncertainty is how many scam attempts will follow—but the underlying threat model (phishing toward seed phrases) is already clear from Trezor’s own assessment.
https://www.cryptobreaking.com/trezor-confirms-data-breach-impacts/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Trezor%20Confirms%20Data%20Breach%20Impacts%2067K%20More%20U.S.%20Customers%20
Comments
Post a Comment