Trezor Data Breach Exposes 67,000 More US Customers
Trezor has expanded its data breach disclosure, saying a failure by logistics provider ShipMonk to delete customer records exposed the personal and order details of about 67,000 additional US customers. The affected users placed orders between November 2019 and August 2021. Exposed data reportedly includes names, email addresses, phone numbers, shipping addresses and order numbers.
Trezor said its own systems, hardware wallets, private keys and wallet balances were not compromised. The company initially estimated that 14,000 customers were affected. In January 2024, it also warned that about 66,000 users who had contacted customer support since December 2021 could face phishing risks.
The Trezor data breach increases the threat of targeted crypto phishing, scam calls and physical security risks. Attackers could use leaked information to impersonate Trezor and request seed phrases or persuade users to sign malicious transactions. Hacken said impersonation attacks accounted for $306 million of the crypto industry’s $482 million in losses during the first quarter. Traders and wallet users should verify communications independently and never share seed phrases or approve unfamiliar transactions.
Neutral
The breach does not involve a cryptocurrency protocol, token network or direct loss of wallet assets, so it is unlikely to create a sustained price effect for any specific cryptocurrency. In the short term, affected users may reduce activity, move funds or sell assets temporarily because of phishing concerns, but this would likely be limited and scattered. The larger impact is on crypto security sentiment and hardware-wallet users rather than market-wide liquidity.
Over the longer term, repeated data breaches could increase demand for privacy-focused delivery, stronger customer-data controls and alternative custody practices. However, the incident does not indicate that private keys or balances were accessed. Historical reactions to similar security disclosures suggest brief risk aversion, followed by limited market impact when core blockchain systems remain secure. The expected price impact is therefore neutral.