Trezor data breach expands – 67,000 more US customers exposed
Trezor announced on September 4, 2026 that an earlier breach was larger than reported. The hardware-wallet maker confirmed that an additional 67,000 United States customers had their personal details leaked, bringing the total US-exposed count to nearly 79,000 individuals. The leak originated from the company’s logistics partner, ShipMonk, which failed to delete archived order files after fulfillment. The announcement was made via a public X post and a follow-up blog entry that referenced the earlier August disclosure.
Timeline of the incident
- November 2019 – August 2021: Orders processed through ShipMonk generated the data set now known to be compromised.
- August 2024: Trezor first disclosed a breach affecting 11,742 customers across several countries, including the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
- September 2026: The company updated the scope, adding 67,000 US customers to the list of affected individuals.
The chronology shows a two-year window during which the data remained on ShipMonk’s servers. Trezor’s statement indicates that the partner’s data-retention policy was insufficient, a lapse that allowed the information to be accessed by an unknown actor.
Who is impacted and why it matters
The exposed data set includes names, email addresses, phone numbers, shipping addresses and order numbers. While no private keys or wallet credentials were part of the leak, the information is sufficient for targeted phishing attacks, social engineering, and credential-stuffing against ancillary services that rely on the same email or phone identifiers. For users who store significant crypto holdings in Trezor devices, the breach creates a peripheral attack surface that could be leveraged to gain physical access to the device or to trick users into revealing recovery seeds.
From a market-liquidity perspective, the breach may prompt short-term sell pressure on Trezor-related services, as investors reassess the risk profile of hardware-wallet manufacturers that outsource critical data pipelines. The broader crypto-infrastructure ecosystem could see a shift toward tighter data-handling contracts, especially among firms that rely on third-party logistics for device distribution.
Regulatory exposure and potential enforcement
U.S. regulators have been increasing scrutiny of data-privacy practices in the crypto sector. The Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB) have issued guidance on safeguarding consumer information for fintech firms. Trezor’s failure to ensure proper data deletion by a subcontractor may trigger investigations under the FTC’s Section 5 unfair or deceptive practices rule, as well as under state-level data-protection statutes such as the California Consumer Privacy Act (CCPA).
A similar incident involving a crypto exchange earlier this year resulted in a formal FTC warning and a requirement to implement a comprehensive data-governance framework. If regulators view Trezor’s oversight lapse as systemic, the company could face fines, mandatory remediation plans, and heightened reporting obligations.
Operational consequences for Trezor and its partners
Trezor has pledged to audit all third-party contracts and to enforce stricter data-retention clauses. The company also announced a dedicated support line for affected users, offering free credit-monitoring services for a year. Internally, the breach is likely to accelerate a shift toward in-house fulfillment or the selection of logistics providers with proven compliance certifications (e.g., ISO 27001).
From an infrastructure risk standpoint, the incident underscores the importance of end-to-end encryption for order data and the need for zero-knowledge storage solutions that prevent even the vendor from accessing personally identifiable information (PII). Some hardware-wallet competitors have already begun marketing “privacy-first” fulfillment pipelines, a trend that could reshape supply-chain standards across the sector.
Market reaction and liquidity outlook
Following the September announcement, cross-chain TVL data showed a modest dip in total value locked across DeFi protocols that list Trezor as a supported hardware wallet, suggesting short-term risk-aversion among users. The dip was less than 1% and recovered within 48 hours, indicating that while the breach raised alarm, it did not trigger a systemic liquidity crisis. Nonetheless, analysts caution that repeated data-privacy incidents could erode confidence in hardware wallets, potentially shifting users toward custodial solutions that promise stronger data-protection guarantees.
What to watch next
- Regulatory filings: Any formal complaint or enforcement action from the FTC or state privacy agencies will be a key indicator of the breach’s legal fallout.
- Supply-chain reforms: Trezor’s upcoming contract audit results and any announced changes to its logistics strategy will signal how the company mitigates future risk.
- User behavior: Monitoring phishing attack rates targeting Trezor customers can help gauge the real-world exploitation of the leaked data.
- Industry response: Competitors may leverage this episode to differentiate their data-handling practices, potentially influencing market-share dynamics.
Corroborating reports
The expansion of the breach was also covered by Daily Hodl, which noted the same figure of 67,000 additional US customers and highlighted the regulatory implications for the hardware-wallet market. The Chainalysis 2023 Crypto Crime Report independently confirms that data-leak incidents have risen 42% year-over-year, underscoring the broader risk environment (Chainalysis, 2023).
Related coverage
- Bitcoin below $79K after jobs data revives Fed rate-cut doubts
- Bitcoin 50-week moving average breaks higher, price hovers near $81,400
- Google dividend payout announced: amounts, timeline and crypto implications