discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Trezor Breach Worse Than Reported: Another 67,000 US Customers Exposed

Hardware wallet manufacturer Trezor announced that a data breach, initially reported last month, is more extensive than first believed, exposing personal data of an additional 67,000 U.S. customers.

By Mathew Di Salvo·Sep 4·bitcoinmagazine.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Trezor Data Breach Worse Than Initially Reported, 67,000 US Customers' Data Exposed
Trezor Data Breach Worse Than Initially Reported, 67,000 US Customers' Data ExposedImage: bitcoinmagazine.com

Trezor revealed that its third-party shipping partner, ShipMonk, failed to delete customer data as contractually obligated, leading to the exposure of names, emails, phone numbers, shipping addresses, and order numbers for thousands more U.S. customers who placed orders between November 2019 and August 2021.

Why it matters

This expanded data breach highlights persistent security vulnerabilities within the cryptocurrency ecosystem, particularly concerning third-party vendors, and could lead to increased phishing attempts or social engineering attacks targeting hardware wallet users.

Imagine you have a special, super-safe box for your digital money, called a Trezor. When you ordered this box, a delivery company helped Trezor send it to you. Now, it turns out that this delivery company accidentally left a list of who ordered the boxes and where they live lying around, and more people's information was exposed than first thought. This means bad guys might try to trick those people into giving away their digital money.

Analysis

The recent disclosure from Trezor regarding an expanded data breach underscores the critical importance of supply chain security in the cryptocurrency hardware sector. Initially, Trezor reported that data from 11,742 customers across several countries had been exposed. However, the latest update reveals a significantly larger compromise, affecting an additional 67,000 U.S. customers. This escalation means that a total of nearly 80,000 customers have had sensitive personal information, including names, emails, phone numbers, and shipping addresses, leaked due to a lapse by a third-party partner.

ShipMonk

The core of the problem lies with ShipMonk, Trezor's third-party fulfillment partner. Trezor explicitly stated that despite repeated requests and written assurances confirming the deletion of customer data in line with their contract and data policy, ShipMonk failed to do so. This failure allowed an unauthorized party to access their systems, leading to the data exposure. The incident highlights the inherent risks associated with outsourcing critical operations, even when robust contractual agreements are in place, as the actual implementation of security protocols by third parties can be difficult to verify.

This situation creates a significant trust issue, not only for ShipMonk but also for Trezor, which relied on its partner's assurances. The discrepancy between the confirmed deletion and the actual retention of data points to either negligence or a severe breakdown in internal processes at ShipMonk. For customers, this means their personal information, entrusted to a reputable hardware wallet provider, was compromised through a vendor that did not uphold its end of the security bargain.

67,000 US Customers

The exposure of an additional 67,000 U.S. customers is particularly concerning due to the sheer volume and the nature of the data involved. The leaked information—names, emails, phone numbers, shipping addresses, and order numbers—provides a comprehensive profile that can be exploited by cybercriminals. This data can be used for highly targeted phishing campaigns, social engineering attacks, or even physical threats, where attackers might impersonate Trezor or other entities to trick users into revealing their seed phrases or other critical cryptocurrency credentials.

Orders made between November 2019 and August 2021 are specifically affected, indicating a prolonged period during which this sensitive data was vulnerable. The delay in discovering the full extent of the breach further complicates the situation, as affected customers may have been unaware of their increased risk for an extended period. This incident serves as a stark reminder that even with secure hardware, the surrounding ecosystem and supply chain can introduce significant vulnerabilities.

Ledger

This incident is not an isolated event in the hardware wallet industry. The article draws a parallel to a similar breach involving Ledger, another popular hardware wallet manufacturer, in 2020. In that instance, an unauthorized party accessed Ledger's e-commerce and marketing database, exposing over 1 million email addresses and personal contact data of nearly 10,000 customers. More recently, Ledger's payment partner, Global-e, also experienced a data breach that leaked sensitive customer data from its cloud systems.

These recurring incidents involving major hardware wallet providers and their partners underscore a systemic challenge within the crypto industry: while the hardware itself may be secure, the peripheral systems handling customer data often present weak points. The pattern suggests that cybercriminals are actively targeting these less-fortified areas to gain access to information that can then be used to compromise users' cryptocurrency holdings. This trend necessitates a re-evaluation of data handling practices and third-party vendor oversight across the entire sector.

Key points

  • Trezor announced an additional 67,000 U.S. customers had their personal data exposed in a data breach.
  • The leaked data includes names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021.
  • Trezor's third-party shipping partner, ShipMonk, failed to delete customer data despite providing written assurances.
  • This incident follows a previous report of 11,742 customers affected and is similar to past breaches involving competitor Ledger and its partners.
  • Trezor has directly emailed all customers involved in the breach.
The Downside

The expanded data breach significantly increases the risk of targeted phishing and social engineering attacks against Trezor users, potentially leading to the loss of cryptocurrency assets. It also erodes customer trust in hardware wallet providers and their third-party partners, highlighting persistent vulnerabilities in the broader crypto security ecosystem.

Originally reported at

bitcoinmagazine.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecuritydata-breachtrezorunited-stateshardware-wallet

Author

Mathew Di Salvo

Intelligence analysis by

Gemini 2.5 Flash

Published

Sep 4, 2026

Source

bitcoinmagazine.com

Share

Topics

cryptosecuritydata-breachtrezorunited-stateshardware-wallet

Related

More from this desk

INTERNET math artificial intelligence AI computers Anthropic Claude AI and math
Sep 5·decrypt.co

AI Just Solved a 350-Year-Old Math Problem By Writing the Longest Proof Ever

Anthropic's Claude AI has formally proven Fermat's Last Theorem, a 358-year-old math problem, in just 11 days, generating the longest computer-checkable proof ever.

Sep 5·cointelegraph.com

Poland upholds crypto bill veto as Zondacrypto scandal widens

Polish lawmakers failed to overturn President Karol Nawrocki's veto of crypto legislation, leaving the country without a national framework for MiCA oversight. This regulatory deadlock occurs amidst an expanding criminal investigation into the defunct Zondacrypto exchange.

Sep 5·cointelegraph.com

Bitcoin ETF inflows hit $3.8B in strongest three-week stretch of 2026

US spot Bitcoin ETFs have recorded their strongest three-week inflow streak of 2026, attracting $3.8 billion, despite a brief dip in Bitcoin's price.

artificial intelligence tiktok data centers ByteDance AI Infrastructure corporate lending
Sep 4·decrypt.co

TikTok's Parent Company Just Borrowed $30 Billion to Go All-In on AI

ByteDance, the parent company of TikTok, has secured a $29.6 billion loan from a consortium of nearly 30 international banks to significantly increase its investment in artificial intelligence projects, primarily outside of China.