Security

Trezor Data Breach Widens: 67,000 More Customers Exposed via ShipMonk Fulfillment Partner

3 min read
Trezor Data Breach Widens: 67,000 More Customers Exposed via ShipMonk Fulfillment Partner

Trezor said Friday that a breach at its shipping provider ShipMonk exposed the personal data of roughly 67,000 additional U.S. customers. That comes on top of nearly 13,700 it had already disclosed last month.

The Czech hardware wallet maker said ShipMonk notified it on Sept. 2 that the incident was larger than first reported, according to The Block. The newly identified records cover orders placed between November 2019 and August 2021. Names, email addresses, phone numbers, shipping addresses, and order numbers are all in the mix.

Trezor first disclosed the breach on Aug. 13. At the time, it said 11,742 customers had full contact details exposed and another 1,947 had names, cities, and emails leaked. That was 13,689 in all. The new figure pushes the cumulative count to roughly 80,700 affected buyers, Decrypt reported.

“Two days ago, we received an update from our shipping provider, ShipMonk,” Trezor wrote in an X post on Sept. 4. “We’re deeply saddened to share the news that the recent data breach affects more customers than originally thought.”

The company said it has emailed every customer in the newly identified batch. Trezor’s own systems were not compromised. Devices, private keys, and wallet backups remain untouched.

What makes this worse is the age of the data. When Trezor disclosed the breach in August, it pointed to a 90-day deletion policy it said it had negotiated into ShipMonk’s fulfillment terms. Records dating to 2019 undercut that claim. Some exposed entries are close to seven years old.

“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said, referring to written assurances from ShipMonk that the information had been purged.

The breach traces to a critical SQL injection flaw in the analytics tool Metabase, disclosed on Aug. 6. The vulnerability let unauthenticated attackers steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk reportedly received extortion emails attributed to the hacking group ShinyHunters, though that attribution remains unconfirmed, Decrypt wrote.

For hardware wallet buyers, the risk is specific. A list that ties a name and a home address to a Trezor order tells an attacker the household probably holds crypto. David Sehyeon Baek, a cybercrime consultant, told Decrypt that a letter carrying a name and home address signals “we can locate you,” and stolen data stays useful for years because people rarely move or change their numbers.

Trezor warned affected customers to watch for scam emails, fraudulent calls, letters, and potential physical security risks. The parallel to Ledger is hard to miss. A 2020 breach at Ledger exposed data on more than 270,000 customers. Years later, Ledger owners were still reporting scam phone calls and forged letters. Some were printed with holograms, QR codes, and fake executive signatures, demanding recipients activate a fictitious security check or lose wallet access, The Block reported.

Owners of both Trezor and Ledger were already receiving such forged letters as recently as February.

Phishing and social engineering drove the majority of the crypto industry’s losses in the first quarter of the year. The two categories accounted for $306 million of the $482 million lost, according to blockchain security firm Hacken, Cointelegraph reported.

Trezor said it is working to ship anonymous delivery as quickly as possible. The option uses locker pickup, neutral packaging, and generic sender details so buyers need not hand over a home address.

Whether ShipMonk faces regulatory fallout is not known. The precise count of affected customers could shift again. Trezor gave the new figure as “approximately 67,000.”

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.