Bitcoin Security Alert: Trezor Data Breach Affects 13,689 Customers

BTC

BTC/USDT

$63,118.00
+0.17%
24h Volume

$9,520,252,348.81

24h H/L

$63,247.05 / $62,535.24

Change: $711.81 (1.14%)

Long/Short
67.9%
Long: 67.9%Short: 32.1%
Funding Rate

+0.0050%

Longs pay

Data provided by COINOTAG DATALive data
Bitcoin
Bitcoin
Daily

$63,047.68

0.01%

Volume (24h): -

Resistance Levels
Resistance 3$64,722.54
Resistance 2$63,909.44
Resistance 1$63,081.52
Price$63,047.68
Support 1$62,706.29
Support 2$61,685.66
Support 3$57,800.19
Pivot (PP):$63,065.42
Trend:Downtrend
RSI (14):42.9
(06:52 AM UTC)
4 min read
AI SummaryAI
  • Trezor confirmed a ShipMonk data breach affected 13,689 customers while its own systems and hardware wallets were not compromised.
  • The Trezor incident exposed names, email addresses, phone numbers, and delivery addresses for 11,742 users, with 1,947 others partly affected.
  • France’s DGFiP confirmed that hacker Zerobytes stole records from 678,438 taxpayers, including address and property information.
  • DGFiP said the intrusion occurred on June 12 and that website login credentials were not included in the stolen material.

Crypto News

Bitcoin (BTC) self-custody users are facing a new phishing threat after hardware wallet maker Trezor confirmed that ShipMonk, its third-party shipping and logistics provider, suffered a data breach affecting 13,689 customers. Trezor said on August 13 that its own systems were not compromised and that no private keys, seed phrases, or device firmware were exposed. The leaked data, however, includes personally identifiable details that can be used to craft convincing attacks. According to the company’s incident notice, 11,742 affected users had names, email addresses, phone numbers, and delivery addresses exposed, while another 1,947 had names, cities, and email addresses accessed. The company emphasized that the hardware devices remain secure because funds are controlled by cryptographic keys held offline, not by shipping records. The practical danger is social engineering: attackers can impersonate Trezor support, banks, exchanges, or courier services and pressure victims into revealing recovery phrases or signing malicious transactions. Trezor warned that affected customers should treat unexpected emails, calls, and physical mail with suspicion, particularly messages that reference a recent device purchase or delivery. The incident also underlines how security around all-time-high market conditions can become more urgent, as higher prices tend to increase incentives for fraud and coercion. Even users who rely on an AI crypto wallet or other automated custody tools should assume that personal contact details circulating on leak markets can be combined with public blockchain activity to identify targets. No loss of Bitcoin has been tied to the ShipMonk breach so far, but the exposed dataset creates a direct path toward targeted phishing, extortion calls, and physical theft attempts. Trezor also reiterated that legitimate support staff will never request a 12- or 24-word recovery phrase, and any message asking for such a phrase should be treated as hostile. Users should verify support domains carefully, avoid clicking links in unsolicited breach notices, and confirm unusual order details only through official account dashboards.

France’s tax administration is dealing with a separate but related data-security failure that has heightened concern among digital-asset holders. The Directorate General of Public Finances, known as DGFiP, confirmed that a hacker using the alias Zerobytes stole records belonging to 678,438 taxpayers, including address and property information. The agency’s public statement said the intrusion occurred on June 12 and that access was immediately suspended for the accounts linked to the confirmed incident. It added that website login credentials were not part of the stolen material and that additional controls have been introduced. The agency acknowledged that the intrusion was sophisticated enough that access controls then in place did not detect the data theft as it occurred, while also indicating that the attacker did not obtain the entire taxpayer database. DGFiP said it will notify affected individuals and professionals by email or postal mail, specifying which records were viewed or extracted. The dataset is reportedly being offered for sale for several thousand euros, raising the possibility that criminal buyers could use it to locate high-net-worth households. For French crypto owners, the concern is not tax administration itself but the physical-security risk created when addresses, property holdings, and financial profiles are combined. Social media commentary has focused on so-called wrench attacks, in which victims are coerced into surrendering access to assets. France has already seen such cases: as of April, authorities had indicted 88 people across 12 crypto-related kidnapping investigations, with 41 attacks registered. Alexandre Stachtchenko, strategy and communications head at Bitstack, urged a pause on state collection of personal data until authorities can prove they can protect existing records. The episode also shows how a leaked taxpayer file could be cross-referenced with exchange disclosures, public payments, or even promotional airdrop claims to build a more complete financial profile. For holders of Bitcoin and any altcoin, the operational lesson is that privacy failures outside the blockchain can still endanger assets held on-chain.

COINOTAG’s analysis treats these incidents as one pattern: the attack surface around Bitcoin is moving from protocol code to personal data. The primary post-mortems, not on-chain transfers, show no private key compromise and no blockchain transaction has been linked to stolen funds. Trezor’s disclosure identifies a logistics vendor as the failure point; DGFiP’s statement identifies an internal-access breach and a 678,438-record taxpayer file. The remediation is therefore identity-security, not wallet software: verify communications, minimize data exposure, and assume leaked records can be used for coercion. For high-value holders, operational security should include independent contact verification, hardware-key isolation, and reducing public links between identity and wallet addresses.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Sarah Chen

Sarah Chen

COINOTAG author

View all posts
AI-AssistedMarket Analyst·Sarah Chen is a market analyst specializing in technical analysis and risk management for cryptocurrency markets, with five years of active trading desk experience.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments