Scope of Breach Widens
Trezor announced an expansion of a previously disclosed data breach affecting its customer base, according to reports from Decrypt and Cointelegraph. The hardware wallet manufacturer confirmed that 67,000 additional US customers had their information exposed through a third-party shipping provider's security incident. The breach represents a significant widening of an already troubling incident, as the company had previously disclosed customer data exposure but did not initially specify the full scale of the compromise.
What makes the latest disclosure particularly concerning is the temporal scope of exposed records. According to Decrypt's reporting, some of the compromised data dates back to 2019—a span of approximately six years. This timeline directly contradicts Trezor's own stated data retention policy, under which the company claimed its partners agreed to maintain customer information for only 90 days before deletion. The discrepancy suggests either a failure in data governance practices or a breakdown in contractual compliance with third-party vendors.
Security Risks and Attack Surface
The exposure of customer information—which typically includes shipping addresses and purchase history—creates a direct attack surface for bad actors targeting cryptocurrency holders. Both Cointelegraph and Decrypt highlighted that the compromised data could enable phishing campaigns and social engineering attacks specifically designed to compromise hardware wallet users. Since Trezor customers represent a security-conscious segment of the crypto market, attackers may attempt sophisticated impersonation tactics leveraging the legitimacy of the Trezor brand.




