- Trezor data breach expands by 67,000 US customers, bringing the known total to about 80,689.
- Exposed records include names, emails, phone numbers, home addresses and order numbers from 2019 to 2021.
- Trezor says wallets, private keys and backups remain secure, but affected owners face phishing and physical safety risks.
Trezor data breach now covers another 67,000 US customers after ShipMonk identified older exposed records. The update raises the known total from 13,689 to about 80,689 customers. The newly identified orders date from November 2019 through August 2021. Exposed information includes names, emails, phone numbers, shipping addresses and order numbers.
Trezor data breach shows records escaped deletion policy
Trezor said it repeatedly sought and received written assurances that ShipMonk deleted records under its contract and data policy. The information should have been removed or anonymized 90 days after delivery.
ShipMonk informed Trezor about the wider exposure on September 2. Trezor then emailed every customer identified in the additional group.
The first disclosure covered 11,742 customers with full exposure and 1,947 with partial exposure. Those figures produced the original 13,689 estimate. Some partial records also came from older orders.
Decrypt reported that the incident traces to a critical Metabase SQL injection flaw disclosed on August 6. The vulnerability allowed unauthenticated attackers to gain administrator access and steal credentials for connected databases. Metabase confirmed active exploitation.
Trezor data breach did not reach the company’s systems, devices, private keys or wallet backups. Exposed shipping records alone cannot provide direct access to wallet balances.
Exposed addresses raise phishing and physical safety risks
The leaked records identify confirmed hardware wallet owners at specific addresses. Criminals can combine order details with emails, calls or letters to create convincing impersonation attempts.
Forged letters have already targeted Trezor and Ledger owners. They used holograms, QR codes and fake executive signatures. The letters directed recipients toward fictitious security checks designed to obtain wallet backups.
Trezor data breach therefore creates an ongoing social engineering risk, even when records are several years old. Trezor tells customers never to share wallet backups or enter them on any website.
Following the Trezor data breach, the company plans anonymous delivery using locker pickup, neutral packaging and generic sender information. The option will also delete shipping identifiers automatically after delivery. Trezor targets an EU launch during September and a US rollout before year-end.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.




