Skip to content

Security3 publishers3 min readPublished Updated

Trezor's 90-day retention clause, not its perimeter, is what capped a 13,689-record loss

The hardware wallet maker says its own systems were untouched; its fulfillment provider ShipMonk was hit. A deletion term Trezor pushed into the contract limited what there was to take.

The Watch · Security desk

Photograph accompanying Trezor's 90-day retention clause, not its perimeter, is what capped a 13,689-record loss
Photo: securityweek.com

What happened

  • Coverage from The Register, as summarised by SC World, indicates that cryptocurrency hardware wallet maker Trezor has confirmed a data breach impacting over 13,000 of its customers.
  • The breach occurred through a third-party shipping partner, ShipMonk, and exposed sensitive personal information.
  • The exposed data includes names, email addresses, phone numbers and shipping addresses for 11,742 customers in several countries.
  • The exposed data also includes names, home cities and email addresses for an additional 1,947 customers.
  • The two disclosed groups total 13,689 affected customers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Trezor, which makes cryptocurrency hardware wallets, has confirmed a data breach affecting more than 13,000 of its customers, according to coverage from The Register summarised by SC World [1]. The intrusion did not happen at Trezor: it happened at ShipMonk, the third-party shipping partner that moves the company's boxes [2].

The numbers are worth reading carefully, because they describe two different exposures. For 11,742 customers across several countries, the leaked set includes names, email addresses, phone numbers and shipping addresses [3]. For a further 1,947, it includes names, home cities and email addresses [4]. That is 13,689 people in total [5], of whom roughly 86 percent now have a full delivery address in the hands of whoever took the data [6].

An email list is a nuisance. A name attached to a residential address, attached to the fact that the person at that address bought a device whose entire purpose is holding bearer assets, is a different category of record. Trezor has told users its own systems remain secure and warned them to expect more phishing [7]. The phishing warning is correct and also the least of it, because the phone numbers and street addresses in the 11,742-record tranche support approaches that do not arrive by email.

The scoping has already moved once. The breach was initially believed to touch only recent orders; newer information indicates older orders may be affected too [8]. This is the ordinary shape of a vendor incident. The company that owns the customer relationship does not own the logs, the retention schedule, or the forensic timeline, so the first number it publishes is the number the vendor was able to give it that day. Operators reading this should assume the same pattern applies to their own fulfillment partners: the initial blast radius is an estimate produced by someone else's incident response team.

The structural point is unglamorous. Anyone shipping physical goods hands a third party the exact dataset that regulators, extortionists and stalkers care most about, and does it as a routine cost of doing business. There is no way to ship a parcel without a name and an address existing somewhere outside your perimeter. Most companies treat that handoff as a procurement question rather than a security boundary, which means it gets a contract and an invoice but not a retention limit, an access review, or a breach clock anyone has tested.

Trezor's remedy is the interesting part of the response. The company is building an "Anonymous Delivery" option, due in the EU in September and in the US by the end of the year, which would let customers complete orders without linking personal identification to their shipping details [9]. That is data minimisation at the vendor boundary rather than a promise to pick better vendors, and it is the only category of fix that survives the next fulfillment breach. It also arrives after the fact for 13,689 people [5].

Worth watching: whether the affected count moves again as older orders are reconciled [8], and whether Anonymous Delivery ships on the stated schedule or slips past the year-end US date [9].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories