In a significant development that has rekindled concerns over the security ecosystem surrounding cryptocurrency hardware wallets, Trezor, a pioneering name in the industry, has quietly confirmed a substantial expansion of a data breach initially disclosed in August. What was first reported as affecting approximately 13,700 customers is now known to impact over 80,000 individuals, with some exposed records dating back nearly seven years. This revelation lends considerable weight to the provocative assertion made in July by prominent blockchain investigator ZachXBT, who controversially labeled all hardware wallets on the market "complete garbage," drawing swift and widespread pushback from the crypto community. The latest update from Trezor, following a series of similar incidents affecting other major hardware wallet brands, underscores a critical vulnerability not in the cryptographic core of these devices, but in the often-overlooked supply chain and third-party vendor relationships that underpin their operations.
The Expanding Scope of Trezor’s Data Exposure
The incident, initially reported by Trezor on August 13, detailed unauthorized access to systems belonging to its shipping provider, ShipMonk. The breach was attributed to an exploit in a third-party analytics platform utilized by ShipMonk, compromising customer order data. At the time of the initial disclosure, Trezor estimated that 13,689 customers were affected. This figure included 11,742 individuals whose full details—name, email, phone number, and shipping address—were exposed, alongside 1,947 customers with more limited exposure of their name, city, and email.
However, a recent update circulated through Trezor’s official social channels has dramatically altered the scale of the incident. The company disclosed that an additional 67,000 U.S. customers who placed orders between November 2019 and August 2021 were also impacted. These newly identified victims had their full details—including name, email, phone number, shipping address, and order number—compromised in the same breach. This brings the total known affected customer count to well over 80,000. A particularly alarming detail is that some of the exposed records now extend back almost seven years, far exceeding any reasonable expectation for how long a shipping partner should retain such sensitive customer data.
Understanding Trezor’s Role in Crypto Security
To fully grasp the gravity of this situation, it is crucial to understand Trezor’s foundational role in the cryptocurrency landscape. Developed by the Czech company SatoshiLabs, Trezor is widely recognized as the first hardware wallet ever introduced to the market. Its core function is to allow users to store their cryptocurrency private keys on a dedicated, physical device that operates offline, thereby isolating these critical keys from internet-connected computers or online exchanges. This offline storage is the fundamental value proposition of a hardware wallet: even if a user’s computer is compromised by malware or other cyber threats, their private keys—and by extension, their digital assets—remain secure and inaccessible on the separate hardware device.
For over a decade, Trezor has meticulously built a reputation for trust and robust security around this promise of offline key management. This makes a breach involving customer data, even if it doesn’t directly compromise the wallets themselves, a particularly damaging event for the brand. The incident erodes the peripheral trust users place in the entire ecosystem surrounding their secure devices, shifting the threat vector from direct wallet compromise to sophisticated social engineering and identity-based attacks.
A Timeline of Trezor’s Data Breach

- August 13: Trezor publicly discloses a data breach involving its third-party shipping provider, ShipMonk. Initial reports state approximately 13,689 customers affected due to unauthorized access to ShipMonk’s systems via a vulnerability in a third-party analytics platform. Exposed data includes names, emails, phone numbers, and shipping addresses.
- September (Undisclosed Date): Trezor issues an update via its official social channels, revealing a significant expansion of the breach. An additional 67,000 U.S. customers are confirmed to have had their full details exposed. This increases the total affected customer count to over 80,000.
- Ongoing: Trezor continues to monitor the situation, advise affected users, and engage with ShipMonk regarding data retention and security protocols. The company emphasizes that its own internal systems and the cryptographic security of its devices remain uncompromised.
Trezor’s Unprecedented Rebuke of Its Vendor
A notable aspect of Trezor’s communication regarding this expanded breach is the unusually direct and public criticism leveled against its vendor, ShipMonk. Trezor explicitly stated that throughout its relationship with ShipMonk, it had repeatedly requested and received written assurances confirming that customer data had been deleted in accordance with contractual obligations, its data privacy policy, and prior communications. Despite these explicit written confirmations, the data was evidently never actually purged from ShipMonk’s systems.
This detail fundamentally alters the narrative of the incident. It transcends a simple case of a vendor falling victim to a hack; instead, it highlights a situation where a vendor, entrusted by a security-focused company, seemingly provided false assurances regarding data handling practices. Trezor’s statement conveyed profound disappointment, particularly given the explicit guarantees it had received. For a company whose entire brand identity is predicated on verifiable trust and meticulous security, discovering that formal compliance confirmations did not reflect the underlying reality of data management is a deeply problematic issue. This issue, moreover, falls outside Trezor’s direct operational control, underscoring the complexities and inherent risks of relying on third-party service providers.
The Specific Risks to Affected Users
While Trezor has consistently maintained that its own systems were not compromised and that no device, private key, or wallet backup was ever at risk (as this sensitive information never touches a shipping provider’s systems), the exposure of identifying and contact information presents a distinct and serious set of threats.
Trezor has specifically advised affected users to remain vigilant against a spectrum of fraudulent activities, including fake emails, deceptive phone calls, and fraudulent letters. More concerning than typical phishing attempts, however, is the potential for risks to physical security. A verified database containing names, home addresses, and confirmation of hardware wallet ownership creates a highly valuable dataset for malicious actors. This information can be leveraged for targeted scams, social engineering attacks, or, in the most severe instances, physical intimidation and theft attempts. Such a scenario represents an evolution of the threat landscape, where attackers move beyond digital exploitation to leverage real-world vulnerabilities. The company has reiterated the paramount rule for all hardware wallet users: never, under any circumstances, share your wallet backup (seed phrase) with anyone, nor type it into any website.
ZachXBT’s July Warning: A Prescient Hot Take?
The expansion of the Trezor breach brings into sharp focus the contentious warning issued by ZachXBT in July. Through his Telegram investigations channel, ZachXBT published what he termed a "hot take," arguing that current hardware wallets were "complete garbage" and unsuitable for critical tasks such as signing transactions or storing substantial funds. He advocated for a safer alternative: a dedicated, separate device used exclusively as a signing tool. He particularly singled out Ledger, criticizing its frequent application and user interface updates for often disrupting previously reliable functionalities.
At the time, ZachXBT’s pronouncement was met with significant resistance and skepticism from a crypto community that largely regards hardware wallets as the pinnacle of digital asset security. His comments were perceived by many as overly alarmist, if not irresponsible, given the industry’s reliance on these devices. However, when viewed against the backdrop of Trezor’s breach nearly sextupling in scope within a single month, ZachXBT’s seemingly "overheated opinion" now reads more like a prescient warning. It suggests that the industry’s leading hardware wallet providers may not have been managing third-party risks with the same rigorous attention to detail that their marketing often implied, or that users implicitly trusted.

A Troubling Trend Across the Hardware Wallet Sector
Trezor’s predicament is not an isolated incident; it appears to be part of a broader, troubling trend impacting nearly every major hardware wallet brand. This context is crucial for understanding the systemic nature of the problem:
- Ledger: The brand explicitly criticized by ZachXBT is currently embroiled in a proposed class-action lawsuit filed on August 27 in the Southern District of New York. The lawsuit seeks at least $500 million in damages, alleging that a December 2023 breach led to approximately $2 million being stolen from the plaintiff’s wallet due to Ledger’s alleged failure to adequately warn affected users. This follows an earlier Ledger data exposure disclosed in January 2026 (likely a typo, perhaps 2021 or 2023), where its third-party payment processor, Global-e, suffered unauthorized access to customer order records, exposing names and contact details in a pattern strikingly similar to the current Trezor incident. The repeated nature of these breaches, particularly involving customer contact information, highlights persistent vulnerabilities in the extended supply chain.
- Coldcard: Another respected name in the hardware wallet space, Coldcard, experienced a significant key-generation/entropy exploit that reportedly allowed attackers to drain between $40 million and $88 million in Bitcoin from affected wallets. This incident, while different in its technical nature (involving a flaw in the device’s random number generation), further contributes to the narrative of evolving and diverse attack vectors targeting hardware wallet users.
- SafePal: In August, SafePal confirmed its own data breach, which was also linked to an order-tracking system rather than the cryptographic security of its wallets. This incident affected nearly 40,000 customers, exposing similar types of identifying information.
Systemic Implications and the Future of Trust
Taken together, these incidents—four major hardware wallet brands disclosing serious security breaches within a relatively tight timeframe—paint a concerning picture. The common thread running through many of these events is not a direct compromise of the devices’ core cryptographic security, but rather vulnerabilities within the surrounding ecosystem. Third-party vendors such as shipping providers, payment processors, and analytics platforms, while external to the wallet’s secure element, hold precisely the kind of customer data that can transform a security-conscious buyer into a highly specific and valuable target for sophisticated attackers.
The implications for the cryptocurrency industry are profound. The core promise of hardware wallets is enhanced security, providing a tangible layer of protection for digital assets. When that promise is undermined by systemic failures in data management and third-party vendor oversight, it erodes the fundamental trust users place in these solutions. This erosion of trust can have several long-term effects:
- Increased Scrutiny and Regulation: Regulators, already grappling with how to oversee the burgeoning crypto industry, may intensify their focus on data privacy, vendor management, and disclosure requirements for hardware wallet manufacturers. Existing frameworks like GDPR and CCPA could be applied more rigorously, potentially leading to significant fines for companies failing to protect user data.
- Shifting User Behavior: Users might become more wary of providing personal information during hardware wallet purchases, potentially exploring alternative acquisition methods or demanding stricter privacy controls from manufacturers. The perceived risk of owning a hardware wallet might increase for some, despite the devices’ inherent security for private keys.
- Enhanced Supply Chain Security Standards: The industry will likely be forced to adopt more stringent vetting processes for third-party vendors, mandate regular security audits, and implement robust data retention and deletion policies across their entire operational supply chain. This could involve contractual clauses with severe penalties for non-compliance and more frequent, independent security assessments.
- Innovation in Privacy-Preserving Procurement: There might be a drive towards developing more privacy-centric purchasing options for hardware wallets, such as anonymous ordering or decentralized fulfillment methods, to minimize the exposure of personal identifying information.
- Re-evaluation of "Gold Standard" Status: While hardware wallets will likely remain a crucial component of crypto security, their status as an unquestionable "gold standard" may be re-evaluated. The industry may need to educate users more thoroughly on the distinction between device security and the security of associated personal data.
In conclusion, the expanded Trezor breach, alongside the challenges faced by Ledger, Coldcard, and SafePal, represents a critical juncture for the hardware wallet industry. While the cryptographic integrity of these devices largely remains robust, the vulnerabilities exposed by these incidents highlight a pressing need for a holistic approach to security—one that extends beyond the device itself to encompass every link in the supply chain and every piece of customer data generated. The industry must learn from these incidents to rebuild and reinforce the trust that is foundational to the secure management of digital assets in an increasingly complex threat landscape.
Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.
Follow us on Twitter @themerklehash to stay updated with the latest Crypto, NFT, AI, Cybersecurity, and Metaverse news!















