Trezor Data Breach Expands to 66,000 More US Users via ShipMonk
Hardware wallet provider Trezor revealed that an additional 67,000 US customers were affected by a data breach at its shipping provider ShipMonk, expanding the incident's scope well beyond earlier estimates. In a Friday X post, Trezor said the breach impacted users who placed orders between November 2019 and August 2021, with ShipMonk failing to delete customer data despite written assurances that it had been removed.
The exposed information includes full names, email addresses, phone numbers, shipping addresses, and order details — data that could fuel phishing attacks and social engineering scams targeting users' digital asset holdings. While Trezor's own systems were not compromised, attackers could impersonate the company to trick users into revealing seed phrases that control their hardware wallets. Trezor warned affected customers to remain vigilant against unsolicited communications requesting recovery seeds or wallet credentials.
Trezor first disclosed the ShipMonk breach in August, initially estimating that only 14,000 users had been impacted. The expansion to 67,000 represents more than a fourfold increase in the affected user base. The company had previously reported a separate security incident in January 2024 involving roughly 66,000 users who contacted its support team since December 2021, underscoring a pattern of third-party and support-vector exposure. Phishing and social engineering scams remain the crypto industry's largest threat category, accounting for $306 million of the $482 million lost in the first quarter of the year, according to blockchain security firm Hacken. In July, a separate crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum, highlighting the ongoing operational risks facing self-custody users.
Read Full Article at CoinTelegraph →