The Trezor customer data breach proved significantly larger than initially estimated in August. An additional 67,000 United States clients joined the original 13,689 victims, as malicious actors acquired order details that the logistics contractor was supposed to purge years ago.
This newly discovered cohort encompasses American patrons who finalized transactions between November 2019 and August 2021. The compromised information unfortunately includes names, electronic mail addresses, telephone numbers, delivery locations, and order identification numbers. Consequently, the total multitude of known casualties now eclipses 80,000 individuals, representing a nearly sixfold expansion from the preliminary assessment.
The Failure of Data Retention Protocols
The fate of these antiquated records proved particularly vexing for Trezor. The corporation mandates that logistical partners obliterate or anonymize order data precisely 90 days following successful delivery. According to the hardware wallet manufacturer, their partner ShipMonk repeatedly provided written affirmations verifying absolute compliance with this directive. Nevertheless, the personal details of clients who purchased devices five, six, and nearly seven years ago inexplicably lingered within the contractor’s digital infrastructure.
Initially, Trezor rationalized the relatively modest scale of the incident by citing this exact 90-day retention policy. During August, the enterprise reported 11,742 patrons with fully exposed profiles, alongside 1,947 users who suffered partial leaks of their names, cities, and email addresses. Subsequent revelations, however, unmasked the harsh reality that the 90-day protocol utterly failed to shield historical transactions.
Uncovering the Metabase Vulnerability
This cascading incident stems directly from a severe Metabase vulnerability, through which attackers infiltrated the ShipMonk databases. The critical flaw, identified as CVE-2026-72898, permitted remote adversaries to execute a sophisticated SQL injection attack via the password reset mechanism. This maneuver granted them unfettered administrative access to the analytical platform instance. At the time of these inaugural incursions, the Metabase developers remained entirely oblivious to the zero-day exploit.
Security Implications and Ongoing Risks
Fortunately, the perpetrators did not compromise the native Trezor systems or the hardware wallets themselves. Cryptographic recovery phrases and private keys remained entirely absent from the stolen datasets. Nonetheless, the dangerous amalgamation of a cryptocurrency owner’s name, telephone number, email, and physical domicile cultivates a distinct and profound peril. Fraudsters can fabricate highly persuasive electronic mail, telephone calls, and traditional postal correspondence while masquerading as Trezor, a courier service, a banking institution, or a digital asset exchange.
Following the reception of this updated intelligence from ShipMonk, the corporation swiftly expanded its casualty registry and dispatched notifications to the newly impacted clientele. Trezor issued a grave, separate admonition regarding potential physical security threats. This leak inextricably links a specific individual and their domestic residence directly to the acquisition of a hardware cryptocurrency wallet.
The manufacturer implores all users to vehemently refuse any requests to input their wallet recovery phrase on any website, regardless of how authentic the solicitation may appear. Ultimately, the ShipMonk debacle illuminates a systemic industry vulnerability. Formal data retention deadlines offer negligible sanctuary if a contractor perpetually harbors ancient records, even after furnishing written confirmation of their destruction.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.