This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$62,940-0.06%ETH$1,878-0.14%SOL$75.15-0.23%XRP$1+0.24%DOGE$0.07+0.02%ADA$0.1792-0.51%Total Cap$2.27T+0.29%Layer Index43 Neutral
BreakingExternal Reporting公開 1日前

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach
Publisher theregister.com 3 分で読める
Image via theregister.com

Layer Index

43

↑ 4 pts in 24h

Security

Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach

Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down

Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000 customers.

The company's initial findings suggested the breach was limited to orders placed in certain countries during the previous 90 days. New information indicates that earlier orders may also be affected.

The breach exposed the names, email addresses, phone numbers, and shipping addresses of 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8.

An additional 1,947 customers had their names, home cities, and email addresses exposed. Some members of this group may have placed their orders before May 10.

"We are verifying this information and the timeframe with ShipMonk," said Trezor.

ShipMonk is Trezor's logistics partner. It stores and ships products on the company's behalf and collects the information needed to fulfill orders.

ShipMonk is subject to Trezor's 90-day retention policy, which requires partners to delete or anonymize customer data within 90 days of collecting it for an order.

ShipMonk did not immediately respond to a request for comment.

Trezor markets itself as a purveyor of secure, offline, hardware-based cryptocurrency wallets. With its products, it aims to shield customers from cyberattacks and malicious apps.

While it assured customers that its own systems and devices remain secure, Trezor warned that "affected customers could experience an increase in phishing attempts."

The exposed details could help criminals craft convincing phishing attempts impersonating banks, crypto exchanges, or Trezor itself.

The company said it contacted affected customers directly and advised them to check any communications against information published through its official channels.

"Never enter your wallet backup on a website or share it with anyone," Trezor said in an apologetic advisory.

"This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses.

"We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected."

Trezor said in a supplementary social media post, separate from the advisory, that its "top priority" project at the moment is to establish an "Anonymous Delivery" option for customers.

The service will allow buyers to complete checkout without linking their home address or real-world identity to an order.

Customers using Anonymous Delivery will go through a dedicated checkout, use a nickname or label ID in place of a real name, and have their product shipped to an automated delivery locker instead of their home. 

The delivery will also come in unbranded packaging with a generic sender label. The carrier will only use email or SMS to send a PIN for the locker.

Trezor said the service is gearing up for a September launch in the EU and by the end of the year in the US.

Alas, that didn't stop Cake Wallet, a rival crypto wallet, from poking fun at Trezor.

"Another rough day for self custody," it Xeeted, before suggesting crypto holders instead use an old smartphone with Cake Wallet installed because "there is no order, no shipping address, or customer data tied to the purchase." ®

速報

速報を見逃さない

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by theregister.com

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

関連記事