Trezor Data Breach Exposes 67,000 More Customers
Trezor data breach widens to affect 67,000 more US customers, with records dating back to 2019 beyond stated 90-day retention policy.

The update
Trezor has revealed that an additional 67,000 U.S. customers were affected by a data breach at its shipping provider, ShipMonk. The exposed records cover orders placed between November 2019 and August 2021, including names, phone numbers, and home addresses. This brings the total number of affected customers to approximately 80,700, significantly higher than the initial estimate of 13,689 customers.
Why it matters
The breach exposes a critical gap in Trezor’s data security practices. The company had stated that its partners had agreed to a 90-day data retention policy, but some exposed records date back to 2019—years beyond this timeframe. While Trezor’s own systems were not compromised and customer wallet keys remain safe, the personal information could be used for sophisticated phishing attacks and social engineering scams targeting hardware wallet owners.
What to watch
Watch for increased phishing attempts targeting affected customers, as attackers may use the exposed information to impersonate Trezor support staff. Monitor how Trezor responds to questions about its data retention policies and whether it takes additional steps to verify partners’ compliance with data handling agreements. The breach also raises questions about the broader security practices in the crypto hardware wallet industry.
Sources
- decrypt.co — Details on the expanded breach scope and timeline
- cointelegraph.com — Information on potential phishing risks and previous security incidents
How did this story land?
Choose one reaction. Choosing it again leaves it selected.
