Trezor breach victim count surges to six times original estimate after discovery of supposedly erased shipping records
Trezor’s disclosure that a third-party logistics breach exposed roughly 80,689 customers, not the initially reported 13,689, underscores how supply chain vulnerabilities can compound data protection risks in hardware wallet distribution. The revelation that supposedly deleted shipping records persisted for years raises questions about vendor compliance verification across the crypto security industry.
- Trezor’s total affected customer count rose to approximately 80,689 after a September 4 update revealed 67,000 additional U.S. customers beyond initial August 13 disclosures.
- Exposed records spanned November 2019 through August 2021 despite Trezor’s 90-day data retention policy and ShipMonk’s written assurances of deletion.
- ShipMonk’s systems were breached through an August zero-day vulnerability in Metabase analytics software, enabling bulk database downloads without compromising Trezor’s wallet systems or cryptographic keys.
- 80,689 Total affected customers across both breach disclosures versus initial estimate
- 67,000 Additional U.S. customers revealed in September update versus August disclosure
- 90 days Trezor’s stated data retention window before deletion from vendor systems
- Aug 2021 Latest date in exposed records supposedly deleted years before breach
Hardware wallet manufacturer Trezor disclosed a substantial expansion of a data breach originating at logistics provider ShipMonk on September 4, revealing that customer records for approximately 67,000 additional U.S. buyers had been exposed. The new figure, combined with the 13,689 customers Trezor reported on August 13, suggests a total impact of roughly 80,689 affected individuals, though Trezor has not disclosed whether the two groups overlap or published a unified customer count. The breach compromised names, email addresses, phone numbers, shipping addresses and order numbers spanning from November 2019 through August 2021, data that ShipMonk had reportedly deleted from its systems years before the incident occurred.
The incident represents one of the most significant supply chain security events affecting the cryptocurrency hardware wallet industry, which has long positioned itself as a more secure alternative to holding digital assets on centralized exchanges. While hardware wallet manufacturers typically emphasize the security of their devices themselves, the distribution chain remains a critical vulnerability point that many customers overlook when evaluating security risks associated with their purchases.
ShipMonk Allegedly Retained Records Despite Deletion Assurances
Trezor’s publicly stated data retention policy requires that customer information be removed from both its own systems and those of fulfillment partners within 90 days, with limited carve-outs for unresolved orders. The company said it had repeatedly requested and received written assurances from ShipMonk confirming that older customer data had been deleted. However, records from 2019 to 2021 persisted in ShipMonk’s systems despite these assurances, a discrepancy Trezor’s own statements had initially downplayed.
Trezor’s August 13 disclosure stated that older order data had already been removed, but an August 14 clarification acknowledged some partially exposed records included older orders. The September 4 update fully reversed this position, disclosing that records spanning two years remained accessible. The pattern of shifting disclosures raises questions about Trezor’s audit procedures and the broader practice of relying on vendor attestations without independent verification or evidence of data destruction.
Industry observers note that many hardware wallet companies and other security-focused vendors contract with third-party fulfillment providers to handle logistics and distribution, creating dependencies on external parties’ security practices. Few companies appear to conduct independent audits or verification processes to confirm that vendors comply with stated data retention policies, instead relying primarily on contractual agreements and periodic written assurances that may not reflect actual data handling practices.
Metabase Zero-Day Vulnerability Enabled Database Access
ShipMonk attributed the unauthorized access to a zero-day vulnerability in Metabase, an open-source analytics platform commonly used by businesses for data visualization and analysis. The vulnerability, disclosed in August, could generate a session tied to an administrator account and facilitate bulk downloads of database tables without typical authentication barriers. This type of flaw in peripheral business tools creates direct pathways to sensitive customer databases, even when the primary systems remain secure.
The Metabase vulnerability exemplifies a persistent challenge in enterprise security where secondary tools and analytics platforms may receive less rigorous security oversight than core production systems. Many organizations treat analytics and business intelligence infrastructure as lower-risk components, yet these systems often have direct access to comprehensive customer databases and can serve as efficient entry points for attackers seeking bulk data extraction rather than targeted account access.
Trezor emphasized that the breach did not compromise its wallet systems, devices, or cryptographic functions. The company stated that no recovery seeds, private keys, wallet funds or wallet software were exposed. The risks instead stem from the combination of personal identifying information with physical location data tied to specific purchase dates, which attackers can cross-reference with cryptocurrency price movements to identify potentially high-value targets for phishing, fraudulent communications or physical targeting.
No Confirmed Downstream Attacks Documented to Date
Trezor notified all newly affected customers by email and stated that anyone who did not receive an incident notice was not impacted by the breach.
The company warned that exposed contact and order information could enable convincing phishing emails, fraudulent phone calls, letters and potentially physical targeting of customers. Social engineering attacks leveraging verified purchase information typically achieve higher success rates than generic campaigns. As of September 4, Trezor had not identified any confirmed downstream attacks resulting from this dataset.
Security researchers emphasize that shipping records pose particular risks for cryptocurrency hardware wallet purchasers because the information confirms that a specific individual at a specific address owns cryptocurrency security equipment. Attackers can use this knowledge to craft targeted phishing campaigns mentioning specific wallet models or impersonate customer support for those devices, dramatically increasing conversion rates compared to untargeted fraud attempts.
The incident underscores how data retention policies provide limited protection without verified vendor compliance and independent audits. For customers in the cryptocurrency space, managing communication security and physical security has become as important as managing digital key security, yet most hardware wallet purchasers remain unaware their shipping records may persist longer than promised by either their hardware provider or the fulfillment vendor serving it. The breach also highlights an emerging expectation that security-focused companies should conduct regular independent security assessments of their supply chain partners rather than relying solely on contractual obligations and written assurances.
