Trezor Data Breach Widens to 67,000 More Bitcoin (BTC) Wallet Buyers

Trezor says 67,000 more US customers were exposed in the ShipMonk breach, lifting the total to roughly 80,700. Devices and seed phrases remain untouched.

(01:25 PM UTC)
4 min read
AI SummaryAI
  • Trezor says 67,000 additional US customers were exposed in the ShipMonk data breach.
  • Exposed records cover orders placed between November 2019 and August 2021.
  • The breach total rose from 13,689 to roughly 80,700 affected customers.
  • The intrusion stemmed from a critical SQL injection flaw in Metabase disclosed August 6.
p9zt4hjs

67,000 More US Customers Exposed

Hardware wallet maker Trezor disclosed on Friday that another 67,000 customers in the United States were swept into the data breach at its shipping partner, ShipMonk — a major widening of an incident first flagged last month. In a statement posted on X, the company said the newly identified records cover orders placed between November 2019 and August 2021, meaning some exposed files are now close to seven years old. Each affected customer's name, email address, phone number, shipping address and order specifics were exposed in full. The expansion came to light two days earlier, when ShipMonk passed on the findings from its own review. Trezor noted it had repeatedly requested and received written confirmation that these records had been deleted, as its contract and data policy required, and expressed disappointment that the provider never followed through. Trezor's own systems were not compromised: device firmware, private keys and wallet backups remain untouched, whether a user's holdings are Bitcoin (BTC), Ethereum (ETH) or assets like Zcash (ZEC). The breach still carries real risk, because the dataset identifies confirmed hardware wallet owners at specific front doors, handing attackers a curated target list for phishing campaigns that impersonate Trezor support and try to trick victims into surrendering the seed phrase controlling their wallets. In August, Trezor initially estimated that only about 14,000 users had been affected. It separately warned in January 2024 that roughly 66,000 users were exposed to phishing risk if they had contacted support since December 2021. With Friday's disclosure, the combined total tied to the shipping-provider incident climbs to roughly 80,700, up from 13,689 at first disclosure.

Metabase Flaw Behind the Leak

The intrusion traces back to a critical SQL injection vulnerability in Metabase, an analytics tool used by enterprises, publicly disclosed on August 6. The flaw let unauthenticated attackers steal credentials for databases connected to the platform, and the same wave caught laptop maker Framework and form builder Tally. ShipMonk has reportedly received extortion emails attributed to the ShinyHunters group, though that attribution remains unconfirmed. The episode underlines how centralized customer databases — home addresses, phone numbers, order histories, the same category of personal data consumers hand to card networks like Visa (V) at checkout — remain single points of failure in ways that decentralized storage networks like Filecoin (FIL) are designed to avoid. Threat actors have already shown how creative they get with hardware wallet data. In February, owners of both Trezor and rival maker Ledger received forged letters printed with holograms, QR codes and fake executive signatures, demanding recipients complete a fictitious “security check” or lose wallet access. Security researchers note that stolen personal data stays usable for years, since people rarely move homes or change phone numbers, and a letter bearing a name and address signals plainly: we can locate you. Impersonation scams exploit human trust rather than code flaws, and the losses are measurable — blockchain security firm Hacken calculated that such scams drove $306 million of the $482 million in total industry losses in the first quarter, and in July one investor lost nearly $1 million after signing a malicious token-approval transaction on Ethereum. Trezor says it is racing to ship anonymous delivery, built on locker pickup, neutral packaging and generic sender details so buyers never hand a home address to the courier at all. Readers tracking the market in real time can follow live spot and futures prices on MEXC.

Seed Phrases Remain the Last Line

Trezor's official X post, which we reviewed, states plainly that the breach affects more customers than originally thought — 67,000 additional US buyers from the 2019–2021 ordering window. Our reading: leaked shipping metadata never touches private keys, but it converts cold-storage holders into prioritized phishing targets. The defense is unchanged — verify every communication channel, never type a recovery phrase into any website, and treat unsolicited “security” prompts as hostile until proven otherwise.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.