Social Lounge Started Sep 4, 2026 2:21 PM

Trezor data leak worse than initially reported

4 replies - 79 views - 2 thanks - 0 tippers - 4 watchers

Sep 4, 2026 2:21 PM
#1

https://x.com/Trezor/status/2095807665603584085

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.

Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed.

All affected customers have been emailed directly. If you didn’t receive an email, then you are not affected.

Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.

Trezor systems were not compromised, and your device is secure. But please be alert for fake emails, phone calls, fraudulent letters, and potential risks to physical security.

NEVER share your wallet backup with anyone or type it into a website.

We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.

2 thanks - 0 tippers - 4 watchers

Replies

Page 1 of 1 - 4 total
Sep 4, 2026 5:27 PM
#3

Crazy. Can't trust third parties whatsoever. I was reading my bank and credit card privacy policies recently. Basically they share all your private information with other financial companies for marketing purposes with no option to opt out. That's why you get junk mail from other credit card companies. And that's probably just the tip of the iceberg. It's also like what Roman Storm's recent post Privacy for Criminals is about...

Real data privacy is not as profitable for banks and makes it more difficult for governments to control their citizens. Meanwhile, real privacy whether in Monero, tornado cash, etc, is also the most secure for the end user because their data isn't getting leaked to third party companies that get breached. It's kind of ridiculous. At this point, banks should be practically obsolete and people can be using decentralized privacy preserving cryptocurrencies that protect their privacy and security better than a bank account. Granted there is more "risk"... but there is also risk with being trapped in a surveillance state with a collapsing currency and debt crisis... etc.

It's really been proven time and time again (especially this year) that hardware wallets cannot be trusted.

0 thanks - 0 tippers
Sep 4, 2026 6:15 PM
#4

Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.

Sounds like a lawsuit

0 thanks - 0 tippers
Sep 4, 2026 6:20 PM
#5

The policy said 90 days too.

If your privacy model ends at “the vendor promised,” it's not privacy, it's theatre

Signature

nullsink // AI inference without identity // no accounts // XMR + BTC

1 thanks - BraveSmoke - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.