
Trezor Data Breach Expands to 67,000 More Customers; Records Span Since 2019
The Trezor hardware wallet breach has grown substantially beyond initial disclosures, with an additional 67,000 customer records now confirmed exposed. Records dating to 2019 emerged, contradicting Trezor's claim that data partners retained customer information for only 90 days.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
Scope of Exposure Widens
Trezor's hardware wallet data breach has expanded to include at least 67,000 additional customer records beyond what the company originally disclosed, according to reports from CryptoPotato and Decrypt. The company had initially characterized the breach as smaller in scale; the discovery of tens of thousands more affected users represents a material revision to the incident's scope.
Records Retained Far Longer Than Promised
Investigators found customer records dating to 2019 among the exposed data, a finding that directly contradicts Trezor's stated data retention practices. The company had announced that its data partners agreed to retain customer information for a maximum of 90 days. The presence of records from 2019—years beyond that 90-day window—suggests either a breach of those retention agreements, a third party's independent failure to delete data as promised, or both.
Outstanding Questions
Neither report indicates which customer categories were newly confirmed as exposed or what information the older records contained. The timeline discrepancy raises questions about whether Trezor had visibility into its partners' actual data handling practices and whether similar retention failures may have occurred at other vendors in the hardware wallet supply chain.
Why It Matters
For Traders
Hardware wallet vendors' credibility directly affects custody confidence; this widening breach and retention contradiction may influence custody decisions for high-value holdings.
For Investors
The exposure gap between Trezor's initial disclosures and the actual breach scope signals potential internal controls failures around vendor oversight and breach investigation rigor.
For Builders
Developers integrating hardware wallet APIs should audit their data retention agreements and assume third-party vendors may retain records longer than stated, then design accordingly.
This article is for information only and is not financial advice. Read the full disclaimer.






