Why did the Trezor data breach expose 67,000 customer records dating back to 2019?

An expansion of the Trezor data breach has revealed that 67,000 additional customers were compromised, with some records dating back to 2019. This discovery highlights a critical failure in data retention policies, as customer information was stored years longer than the promised 90-day window.
Why did the Trezor data breach expose 67,000 customer records dating back to 2019?

The recent expansion of the Trezor data breach reveals that 67,000 additional customers have had their contact information exposed, with some records persisting since 2019. This discovery is particularly alarming because it contradicts Trezor’s public commitment to a 90-day data retention policy. The breach originated from a third-party support provider, demonstrating that even when a hardware wallet manufacturer maintains high internal security, the external vendors they employ can remain a significant point of failure for user privacy.

For US-based crypto investors, this breach is a stark reminder of the 'tail risk' associated with purchasing hardware wallets. While the private keys themselves remain secure on the devices, the leak of names, email addresses, and phone numbers provides bad actors with a roadmap for sophisticated phishing campaigns. In many cases, these leaks have led to 'wrench attacks' or physical threats, as hackers can correlate digital wealth with physical home addresses, a concern that has previously plagued Trezor's competitor, Ledger.

From a regulatory and market perspective, this incident may trigger increased scrutiny from the Federal Trade Commission (FTC) regarding how crypto-adjacent firms handle consumer data. As the US moves toward clearer digital asset frameworks, the security of the 'on-ramp' and 'support' infrastructure is becoming as vital as the blockchain code itself. This breach damages the brand trust that Trezor has built over a decade, potentially pushing security-conscious users toward alternative cold-storage solutions that offer more robust privacy guarantees.

Readers and Trezor owners should remain on high alert for suspicious communications. Because the exposed data dates back to 2019, even those who have not used their Trezor in years may be targeted by scammers. Moving forward, the industry will be watching Trezor’s legal team to see if they pursue action against the third-party partner responsible for the retention failure and whether the company implements more aggressive data-purging protocols to prevent future leaks.