Trezor claims that information of another 67,000 American customers has been leaked
Coinpaper
56m ago
Ai Focus
Trezor claims that the scope of data leakage by ShipMonk has expanded, with an additional approximately 67,000 American customers' information exposed. The risks are concentrated in phishing scams and physical security issues.
Helpful
No.Help

Trezor The latest disclosure shows that the scope of the data breach previously caused by logistics service provider ShipMonk has further expanded, with an additional approximately 67,000 American customers being affected. The relevant records involve orders from November 2019 to August 2021, including names, email addresses, phone numbers, home addresses, and order numbers.

As mentioned by Trezor, ShipMonk reported this new batch of exposed data two days ago. The company stated that according to the contract and data policies between the two parties, these records should have been deleted, and they had received multiple written confirmations from the other party before, but the relevant data was ultimately not truly removed.

The number of affected people has risen to approximately 80,700.

When Trezor first disclosed this matter in August of this year, they attributed the impact to a 90-day deletion policy agreed upon with their contract partners. With the confirmation of new data, the number of affected customers has increased from 13,689 to approximately 80,700.

The company stated that all the newly affected users are located in the United States, and the related orders were placed between November 2019 and August 2021; some of these records are nearly 7 years old.

The risks are concentrated in address and identity information.

Trezor indicates that the company's own system has not been compromised, and the hardware devices, private keys, and wallet backups have not been affected. The more significant issue is that the leaked data can be directly linked to the identified holders of the hardware wallets and their home addresses.

The company reminds users to be wary of forged emails, phone calls, and paper letters, and reiterates that wallet backup phrases should not be disclosed to anyone, nor should they be entered on any websites.

In February this year, both users Trezor and Ledger received forged emails. These emails contained holographic logos, QR codes, and forged signatures of senior executives, demanding that users complete a so-called "security check" or risk losing access to their wallets.

The source of the vulnerability points to Metabase.

The report mentioned that this intrusion is related to a severe SQL injection vulnerability in the analysis tool Metabase. This vulnerability was disclosed on August 6th, allowing attackers to steal credentials from connected databases without authentication. In addition to ShipMonk, Framework and Tally were also involved in the same incident.

Trezor also indicates that ShipMonk received a ransom email allegedly from ShinyHunters, but this attribution has not yet been confirmed.

Additional information:According to Trezor, they are accelerating the rollout of an anonymous delivery scheme, which includes self-pickup from lockers, neutral packaging, and generic sender information, in order to reduce the need for users to provide their home addresses.

Tip
$0
Like
0
Save
0
Views 12
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3 : OpenAI AI agents accused of hacking German websites and making 15,000 edits
OpenAI related, AI, and agents were alleged to have conducted abnormal operations on German websites, and researchers discovered such activities in August.
CoinPedia
·2026-09-04 21:22:25
5
web3: ZEC breaks through $1,000, Zcash ranks among the top ten in market value
ZEC once rose to $1,023, entering the top ten of crypto assets by market value, with approximately $2.3 billion in open futures contracts. The progress of Zcash ETF under Grayscale is receiving attention.
Coinpaper
·2026-09-04 20:59:56
11
Ethereum: Ethereum rebounds, approaching the $2550 resistance level
ETH rebounds to around $2,550; intensive clearing areas, whale transfers, and spot trading ETF Capital flows become the focus of short-term trading.
Cryptonews
·2026-09-04 20:11:51
22
web3: U.S. non-farm payroll data for August to be released tonight; stronger than expected or may suppress the market
U.S. non-farm payroll data for August will be released tonight; if employment is stronger than expected, it could boost expectations for the Federal Reserve to raise interest rates in September and put pressure on the market.
CoinPedia
·2026-09-04 19:47:38
56
View More