WangDou logo
WangDou

Trezor breach grows to 81,000 customers: data that was supposed to be deleted never was

2026-09-04·WangDou AI Express·Web3 / Hardware Wallets / Data Breach

You locked your keys in a hardware wallet and forgot that the shipping label has your front door on it.

Three key facts

From 14,000 affected customers to 81,000. On September 4, crypto hardware wallet maker Trezor disclosed that a breach at its logistics partner ShipMonk was far bigger than first reported. On top of the roughly 14,000 customers it announced on August 13, about 67,000 more U.S. customers had their data fully exposed, bringing the total to around 81,000.

The leaked records were supposed to be gone. The newly found data comes from an earlier partnership between November 2019 and August 2021, and includes names, emails, phone numbers, shipping addresses and order numbers. Trezor says it repeatedly asked ShipMonk to delete that data and received written confirmation that it had, and said it was "very disappointed" to learn otherwise. ShipMonk only told Trezor on September 2.

The way in was a Metabase flaw. ShipMonk says attackers exploited a vulnerability in Metabase, the analytics platform it uses, to reach account and customer data; Metabase alerted ShipMonk on August 6. Trezor stresses its own systems were not compromised and its wallets remain secure, but it warned customers about phishing and acknowledged the data could expose people to physical security risks.

WangDou's Take

Crypto's favorite slogan is "not your keys, not your coins." This breach contains zero private keys and may still be more dangerous than one: it is effectively a list that reads "this household holds crypto, and here is the address." A hacker can't pull coins out of a hardware wallet, but a criminal can knock on the door. Home-invasion kidnappings targeting crypto holders have become grimly common, and for these 81,000 people the risk just moved from the screen to the doorstep.

The most ironic line is "we asked them to delete it and got it in writing." A written assurance does not scrub a server. Trezor sells a security philosophy built on trusting no one, then handed customers' home addresses to a logistics vendor it had no way to audit. This is also its second big leak, after a January 2024 incident exposed about 66,000 users.

Hardware wallet makers should rethink where the real attack surface is. Rather than another layer of protection on the chip, collect one less field at checkout. Pickup-point delivery, addresses that auto-expire after shipping: that beats any security badge in the ad copy.

Source: The Block · BleepingComputer · The Hacker News

Comments

Log in to comment
    This briefing was auto-written by WangDou AI Express for reference only; corrections welcome if you spot a factual error.
    指挥舱👽