RUECAT DEX
All news
The Block 22h ago

Trezor Identifies 67,000 Additional Users Impacted by Partner Security Breach

Hardware wallet manufacturer Trezor revealed an additional 67,000 customers were exposed in a third-party logistics data breach.

Encrypted hardware wallet surrounded by glowing orange data fragments during a Trezor data breach.

A widening supply-chain security incident has prompted hardware wallet maker Trezor to confirm that additional user records were compromised during an external logistics intrusion. The updated disclosure surrounding the Trezor data breach indicates that thousands of historic customer records stored by a third-party partner were accessed without authorization.

According to The Block, approximately 67,000 newly identified customer entries spanning from 2019 to 2021 were caught in the security event at logistics partner ShipMonk. The exposed information includes customer full names, email addresses, phone contact numbers, physical shipping locations, and internal order reference identifiers.

The hardware wallet manufacturer stressed that core security architecture, including recovery seed phrases, private keys, and on-device funds, remained entirely untouched by the external incident. Nevertheless, the exposure of physical addresses and contact information exposes impacted users to heightened risks of targeted phishing campaigns and physical security threats.

Cybersecurity specialists within the digital asset sector have reiterated that third-party vendors remain a critical vulnerability for privacy-focused hardware vendors. When logistics and fulfillment partners retain sensitive customer details beyond necessary operational windows, the resulting attack surface creates long-term exposure risks.

Trezor has advised affected clients to exercise extreme caution regarding unsolicited communications, suspicious email links, and fraudulent customer support requests. Going forward, the broader hardware security industry faces mounting pressure to enforce stricter data purging protocols across all third-party logistical partners.

Key takeaways

  • An additional 67,000 Trezor customer records were exposed via logistics partner ShipMonk.
  • Compromised information includes names, emails, phone numbers, and physical shipping addresses.
  • Private keys and on-device cryptocurrency funds remain completely secure.
Source: The Block