RUECAT DEX
All news
Decrypt 23h ago

Historic Retention Lapses Deepen Impact of Trezor Logistics Partner Data Leak

Trezor customer data dating back to 2019 was leaked in a partner breach, violating agreed-upon 90-day retention policies.

Scattered digital records exposing Trezor customer data over a dark neon cybersecurity background.

Scrutiny over third-party data retention policies has intensified following revelations that sensitive Trezor customer data dating back to 2019 was improperly maintained and ultimately compromised. The development highlighted gaps between contractual privacy agreements and actual logistical data management practices among external vendors.

According to Decrypt, roughly 67,000 additional customer entries were uncovered in the breach affecting shipping partner ShipMonk. Notably, several compromised records originated in 2019, representing a direct contradiction of the 90-day data deletion timeline that Trezor had previously established with its third-party service providers.

The exposed data sets encompass personal identifiers including names, email addresses, phone numbers, and physical residential shipping addresses. While the hardware maker's core cryptographic architecture remains uncompromised, the unauthorized retention of historical customer data has drawn sharp criticism from the security community.

Privacy advocates emphasize that when customers purchase hardware wallets specifically to preserve financial anonymity and security, prolonged retention of shipping metadata poses severe long-term risks. Threat actors frequently cross-reference leaked shipping records with other public databases to construct detailed target profiles for social engineering schemes.

In response to the widened incident, industry analysts anticipate stronger calls for end-to-end cryptographic order handling and decentralized fulfillment options. Hardware wallet manufacturers are now under renewed pressure to audit partner compliance rigorously and guarantee immediate data destruction upon order completion.

Key takeaways

  • Leaked customer records dated back to 2019, exceeding the agreed 90-day retention policy.
  • The incident highlights recurring third-party vendor risks across hardware wallet supply chains.
  • Advocates are urging hardware makers to enforce strict, auditable data purge mechanisms.
Source: Decrypt