Breaking
TRAllegation of violence against Berhan Şimşek: Security camera footage revealedESVolkswagen announces massive adjustment plan and conditions the future of the Seat brandTRForest fire in Balıkesir SındırgıTRTwo people trapped in the tunnel during the flood disaster on the Nepal-Tibet border were rescuedDEComplete closure of the A45 between Lüdenscheid-Nord and Hagen-SüdINHeavy rain causes widespread waterlogging and traffic disruption in Delhi-NCRCRYPTO-TREmployment data in the USA exceeded expectations: Mobility in the marketsINTLDeath of 9-year-old in Arizona group home sparks political controversy and investigationTRPreparations for the National Women's Volleyball Team before the match against SerbiaGLOBALMarkets Weigh Fed Rate Hike Odds Following August Jobs ReportTRAllegation of violence against Berhan Şimşek: Security camera footage revealedESVolkswagen announces massive adjustment plan and conditions the future of the Seat brandTRForest fire in Balıkesir SındırgıTRTwo people trapped in the tunnel during the flood disaster on the Nepal-Tibet border were rescuedDEComplete closure of the A45 between Lüdenscheid-Nord and Hagen-SüdINHeavy rain causes widespread waterlogging and traffic disruption in Delhi-NCRCRYPTO-TREmployment data in the USA exceeded expectations: Mobility in the marketsINTLDeath of 9-year-old in Arizona group home sparks political controversy and investigationTRPreparations for the National Women's Volleyball Team before the match against SerbiaGLOBALMarkets Weigh Fed Rate Hike Odds Following August Jobs Report
BackTrezor Data Breach Impact Expands to 67,000 Additional US Customers
Trezor Data Breach Impact Expands to 67,000 Additional US Customers
Developing
Cointelegraph48 minutes agoTech1 min read

Trezor Data Breach Impact Expands to 67,000 Additional US Customers

Shipping provider ShipMonk failed to delete customer data, exposing names, addresses, and order details of thousands of users.

Quick Look

  • Hardware wallet provider Trezor announced that a data breach involving its shipping partner, ShipMonk, has affected an additional 67,000 US customers.
  • Exposed data includes names, emails, and addresses, heightening the risk of phishing attacks for affected users.

AI-generated summary

Why It Matters

Trezor previously estimated 14,000 users were affected in August. The company also reported a separate incident in January 2024 regarding support team contacts.

Font size

The impact of hardware wallet provider Trezor’s data breach was larger than initially estimated, expanding to an additional 67,000 US customers.

The breach may endanger more US users who ordered between November 2019 and August 2021, Trezor said in a Friday X post, citing the latest update from its shipping provider, ShipMonk.

These customers had their full details exposed, including name, email, number, shipping address and order specifics. Trezor blamed the shipping provider for not deleting the data from these orders, despite saying it had received written assurances from ShipMonk.

While Trezor systems were not compromised, the data breach may threaten the digital asset holdings of the 67,000 customers, as attackers may use the information for phishing attacks impersonating Trezor, in a bid to steal users’ seed phrases controlling their wallets.

In August, Trezor initially estimated that only 14,000 users had their data exposed through the shipping provider. Trezor reported in January 2024 that about 66,000 users were at risk of phishing attacks if they had contacted the company’s support team since December 2021.

Phishing attacks and social engineering don’t require exploiting code vulnerabilities. Still, these impersonation-based scams drove the majority of the crypto industry’s losses in the first quarter of the year, accounting for $306 million of the total $482 million lost, according to blockchain security company Hacken.

In July, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum.

Open Questions

  • Will ShipMonk face legal repercussions for the data retention failure?
  • Are there additional affected regions beyond the US?

Related Topics

This article was originally published by Cointelegraph.

Related Stories

Bitquery Study Shows OP_RETURN Text and Fake-Address Outputs Impose Different Costs on Bitcoin Nodes
Developing·

Bitquery Study Shows OP_RETURN Text and Fake-Address Outputs Impose Different Costs on Bitcoin Nodes

Bitquery analyzed 965,135 Bitcoin blocks to compare four types of text data, finding that OP_RETURN taunt transactions add no spendable state while fake-address text outputs burden the UTXO set with effectively unspendable BTC. The study notes that Bitcoin Core 30.0 increased OP_RETURN relay limits but did not change consensus rules, and that a March 2026 taunt campaign targeting Luke Dashjr used low-cost OP_RETURN messages under the former 80-byte ceiling.

CryptoSlate
2 min read
BIS Prototype Uses XRP Ledger to Authenticate Official Statistics
Developing·

BIS Prototype Uses XRP Ledger to Authenticate Official Statistics

The Bank for International Settlements released a working paper describing a prototype that uses the XRP Ledger to verify the authenticity of official statistics by anchoring cryptographic fingerprints of SDMX files on-chain, enabling independent integrity checks without exposing confidential data, while analyzing the implications for XRP token burn and reserve requirements under various batching scenarios.

CryptoSlate
3 min read
More on this topictrezor