{"id":77707,"date":"2026-09-04T13:20:05","date_gmt":"2026-09-04T13:20:05","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/trezor-data-leak-spirals-as-67000-more-us-buyers-get-exposed\/"},"modified":"2026-09-04T13:20:05","modified_gmt":"2026-09-04T13:20:05","slug":"trezor-data-leak-spirals-as-67000-more-us-buyers-get-exposed","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/trezor-data-leak-spirals-as-67000-more-us-buyers-get-exposed\/","title":{"rendered":"Trezor Data Leak Spirals as 67,000 More US Buyers Get Exposed"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Trezor added 67,000 U.S. customers to its Shipmonk breach on Sept. 4.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Trezor\u2019s leak now covers roughly 80,000 people, including home addresses.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Trezor targets U.S. Anonymous Delivery by the end of 2026.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/x.com\/Trezor\/status\/2095807665603584085?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">The newly identified records<\/a> cover U.S. orders placed between November 2019 and August 2021 and expand an incident that had already affected 13,689 more recent customers across several countries. Altogether, the breach now involves roughly 80,000 people, although Trezor\u2019s systems, devices, private keys, and wallet backups were not compromised.<\/p>\n<h2>Trezor Finds 67,000 More U.S. Customers in the Breach<\/h2>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/trezor-shipping-provider-exposes-13689-crypto-customers-to-scams\/\">Following the last disclosure<\/a>, Trezor said it learned Sept. 2 that the Shipmonk breach was larger than initially reported. The older records contain customers\u2019 names, email addresses, phone numbers, shipping addresses, and order numbers, giving attackers information that could make scams far more convincing.<\/p>\n<figure id=\"attachment_844769\" aria-describedby=\"caption-attachment-844769\" style=\"width:1368px\" class=\"wp-caption aligncenter\"><figcaption id=\"caption-attachment-844769\" class=\"wp-caption-text\">Image source: Trezor security alert via X on Sept. 4, 2026.<\/figcaption><\/figure>\n<p>The discovery is particularly troubling because Trezor says it repeatedly asked Shipmonk to delete the information and received written confirmation that it had been removed. Trezor said the assurances were consistent with its contract, data policy and previous communications with the fulfillment provider.<\/p>\n<p>That also raises questions about Trezor\u2019s advertised 90-day data retention policy with fulfillment partners. The newly discovered records date back years, showing that the policy was not enforced for the affected 2019-2021 U.S. customers.<\/p>\n<h2>Leaked Addresses Push the Threat Beyond Email Phishing<\/h2>\n<p>The information exposed does not allow an attacker to remotely access a Trezor wallet. Private keys and seed phrases, the secret recovery words used to control a crypto wallet, were not part of the breach.<\/p>\n<p>But the type of information <a href=\"https:\/\/news.bitcoin.com\/french-police-expand-crypto-security-after-77-kidnapping-cases-drive-new-protection-push\/\">exposed creates a different problem<\/a>. Trezor warned that leaked phone numbers and home addresses could potentially put affected customers at physical risk, while real order numbers and contact details could help scammers impersonate the company more convincingly.<\/p>\n<p>The breach originated outside Trezor. Attackers exploited a previously unknown SQL-injection vulnerability in Metabase, an analytics platform used by Shipmonk. Metabase notified Shipmonk around Aug. 6, patched the vulnerability and invalidated sessions, while Shipmonk later explained that it secured its systems.<\/p>\n<h2>Third-Party Data Failures Put Hardware Wallet Buyers at Risk<\/h2>\n<p>The incident follows <a href=\"https:\/\/blog.trezor.io\/details-of-the-mailchimp-data-breach-a06872caa1fd\" target=\"_blank\" rel=\"noopener noreferrer\">other third-party exposures<\/a> involving Trezor customers. About 106,856 customers were affected in a 2022 incident, while a compromised support portal in 2024 <a href=\"https:\/\/blog.trezor.io\/trezor-security-update-stay-vigilant-against-potential-phishing-attack-bb05015a21f8\" target=\"_blank\" rel=\"noopener noreferrer\">exposed as many as 66,000 names<\/a> and email addresses. In each case, the hardware wallets themselves were not remotely compromised.<\/p>\n<p>That distinction matters for customers deciding how to respond. Trezor warns that nobody from the company will ask for a wallet backup, meaning customers should never enter their seed phrase into a website or hand it over to someone claiming to provide support.<\/p>\n<h2>Trezor Pushes Anonymous Delivery as Shipmonk\u2019s Future Hangs<\/h2>\n<p>Trezor is now promoting an Anonymous Delivery system designed to reduce the amount of customer information retained during hardware wallet purchases. The system includes locker pickup, neutral packaging, a generic sender, and automatic deletion of shipping identifiers after delivery, with a European launch targeted for September and a U.S. rollout planned by the end of 2026.<\/p>\n<p>For now, Trezor has not announced plans to drop Shipmonk. The company previously said it would determine the partnership\u2019s future after obtaining a complete picture of the incident, leaving that decision unresolved even as the known number of affected customers approaches 80,000. The issue follows a number of scary hardware wallet incidents that have happened in 2026, <a href=\"https:\/\/news.bitcoin.com\/security\/data-breach-hits-39798-safepal-customers-after-order-plugin-flaw\/\">associated with Safepal<\/a> and <a href=\"https:\/\/news.bitcoin.com\/security\/how-bitcoin-hardware-wallets-supported-users-during-the-coldcard-crisis\/\">Coldcard wallets<\/a>.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/trezor-data-leak-spirals-as-67000-more-us-buyers-get-exposed\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Trezor added 67,000 U.S. customers to its Shipmonk breach on Sept. 4. Trezor\u2019s leak now covers roughly 80,000 people, including home addresses. Trezor targets U.S. Anonymous Delivery by the end of 2026. The newly identified records cover U.S. orders placed between November 2019 and August 2021 [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":77708,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77707"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=77707"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/77707\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/77708"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=77707"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=77707"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=77707"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}