Trezor says a former shipping partner retained customer data it had previously certified as deleted, exposing an additional 67,000 customers in the latest fallout from the hardware wallet maker’s vendor security problems.
What Trezor Said About the Customer Data Exposure
Trezor disclosed that a shipping provider held on to customer information the company had expected to be permanently deleted, according to the company’s incident notice. The retained records affected roughly 67,000 additional customers beyond those flagged in earlier disclosures. For related coverage, see Bitwise Says Bitcoin-Gold Correlation Hit Six-Year High.
The core of the disclosure is that data the partner had certified as removed was in fact still being held, as reported by Unchained. Trezor attributed the exposure to the shipping partner rather than to a breach of its own internal systems. For related coverage, see Tether Says KPMG Signed Off on 2025 Books After 2017 Promise.
Why a Shipping Partner’s Data Retention Raises Security Concerns
For a hardware wallet company whose customers explicitly seek to protect their crypto holdings, exposure through a third party is especially sensitive. The incident centers on a vendor keeping records after being asked to delete them, which extends the pool of affected people well beyond Trezor’s direct control. For related coverage, see DOJ Says Hamas Crypto Seizures Hit $560K as FBI Takes Over Fundraising Sites.
The pattern echoes Trezor’s earlier disclosure that a ShipMonk breach exposed names, phone numbers and home addresses of 13,689 customers, underscoring how repeatedly logistics vendors have become the weak link in the company’s data chain.
What This Means for Trezor Customers and the Broader Crypto Industry
When a partner’s controls fail, the reputational cost lands on the primary brand, and Trezor’s guidance to affected users is laid out in its data incident resource. Customers of crypto hardware firms face heightened phishing risk whenever names and contact details leak, since attackers can impersonate the vendor.
The episode fits a wider run of vendor-driven exposures across the sector, including SafePal’s disclosure that a breach exposed order information of nearly 40,000 customers. Together they point to third-party data handling, not on-device security, as the recurring failure point for wallet makers, raising the bar for how these companies audit and verify their logistics partners.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
