Hardware Wallet Breach Expands By 67,000 Users
A prominent hardware wallet manufacturer has disclosed that an ongoing data exposure incident involving its external shipping partner is more extensive than initially reported.
The Prague, Czech Republic-based firm Trezor confirmed on Friday that an additional 67,000 customers located in the United States have been swept into a data leak. Information exposed for this newly identified group includes names, shipping addresses, email addresses, phone numbers, and order numbers.
According to the hardware wallet manufacturer, the newly compromised data stems from orders placed during a specific historical window, spanning from November 2019 through August 2021.
The company previously alerted the public in August that its third-party fulfillment partner, ShipMonk, had suffered a breach resulting from unauthorized access to systems holding consumer information.
Retained Data
The expanding scope of the incident hinges on data retention practices at the third-party logistics provider. Trezor stated in its Friday announcement that ShipMonk had provided false reassurances regarding the erasure of old customer records.
The wallet maker indicated that it had sought continuous verification that historical order details were being properly purged from the fulfillment systems.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor wrote.
The firm expressed its frustration over the discovery that those previous guarantees were inaccurate.

“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” the company stated.
Neither Trezor nor ShipMonk immediately responded to media inquiries regarding the situation.
The newly disclosed figures significantly increase the total number of impacted individuals. During the initial August announcement, Trezor reported that 11,742 customers had their names, phone numbers, emails, and shipping addresses exposed. That initial group spanned users in the United States, the United Kingdom, Brazil, Colombia, Italy, Portugal, and Sweden.
Additionally, a separate subset of 1,947 individuals was identified in the first wave of the breach, though their compromised data was limited to names, emails, and cities.
Trezor stated that it has already sent direct emails to all consumers involved in the unauthorized access. SatoshiLabs, the parent company behind the popular Bitcoin storage solution, previously stated last month that it was actively investigating the incident.
Historical Industry Leaks
Personal data belonging to cryptocurrency users has been repeatedly targeted by cybercriminals over the years.
In 2020, an unauthorized party accessed the e-commerce and marketing database of popular hardware manufacturer Ledger. That incident resulted in the leak of over 1 million email addresses, alongside the personal contact data of nearly 10,000 customers.
At the start of this year, consumers reported receiving emails from Global-e, Ledger’s payment partner, warning that a separate data breach at its cloud systems had leaked sensitive customer data once again.


