Trezor Customer Data Leak: Coins Are Safe, But Phishing Is Inevitable
Trezor, a hardware cryptocurrency wallet manufacturer, reported a data breach at its logistics partner, ShipMonk, affecting around 13,689 customers. The incident, confirmed on August 13, 2026, involved unauthorized access to ShipMonk's systems, which stored order information from May 10 to August 8, 2026. Trezor's own systems and user crypto assets were not compromised.
The leaked data varies: for 11,742 customers, full names, email addresses, phone numbers, and delivery addresses were exposed. For 1,947 others, only name, city, and email were leaked. The breach was limited to customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor warns affected users of an increased risk of phishing attacks, where malicious actors may use the stolen contact details to impersonate Trezor, banks, or exchanges to steal wallet recovery phrases. All impacted customers have been notified via email.
In response, Trezor announced a planned "Anonymous Delivery" feature for the EU (September 2026) and the US (end of 2026), aiming to anonymize logistics data. ShipMonk has not yet issued a public statement on its official website.
The analysis highlights this as a recurring industry pattern where third-party logistics vendors become weak links in the supply chain, storing data longer than necessary. Similar incidents, like the 2020 Ledger breach, led to prolonged phishing campaigns. A key question remains whether hardware wallets can ever fully decouple from external logistics risks.
cryptonews.ruHace 1 hora(s)