Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

A major security breach has rocked cryptocurrency hardware wallet provider Trezor, with a staggering 67,000 U.S. customers’ data potentially compromised in a hacking incident that’s left many wondering how such a massive vulnerability could be overlooked. The breach, which occurred at ShipMonk, a third-party logistics company used by Trezor for order fulfillment and shipping, has raised serious concerns about the security of sensitive user information.

At its core, the issue revolves around “cross-domain privilege escalation,” a complex technical term that refers to the unauthorized transfer of sensitive data between different domains or systems. In this case, hackers exploited a vulnerability in ShipMonk’s software to gain access to Trezor customer data, including names, email addresses, and shipping details. The shocking part? According to Trezor, the compromised data was supposedly deleted after the breach occurred, only to resurface again months later.

The scope of the breach is substantial, with over 67,000 U.S. customers potentially affected by the security lapse. While this number represents a relatively small fraction of Trezor’s global user base, it still underscores the need for robust security measures and tighter vendor management in the burgeoning cryptocurrency space. For perspective, cross-domain privilege escalation can be likened to a house with multiple entrances – if one entrance is breached, an attacker can potentially access the entire property.

Trezor has since issued a statement assuring customers that its own systems were not compromised during the breach. However, this clarification does little to alleviate concerns about the security of third-party vendors used by sensitive businesses like cryptocurrency exchanges and wallet providers. The incident highlights the importance of scrutinizing supply chain partners for vulnerabilities and ensuring robust data protection protocols are in place.

The ShipMonk breach also raises questions about the efficacy of cybersecurity measures in preventing similar incidents from occurring in the future. As hackers increasingly target weak links in complex systems, it’s essential that companies prioritize vendor risk management and adopt more proactive security strategies to mitigate potential breaches. The aftermath of this incident will undoubtedly serve as a wake-up call for businesses across the cryptocurrency ecosystem.

In light of this breach, we urge users of cryptocurrency hardware wallets to remain vigilant about their account security and consider implementing additional measures such as two-factor authentication or encryption to protect their sensitive information. Moreover, companies handling user data should take this incident as an opportunity to review and fortify their own vendor management practices to prevent similar vulnerabilities from emerging in the future.


Source: The Hacker News — 2026-09-05