Trezor Data Breach Exposes Thousands to Potential Physical Attacks
A data breach at Trezor, a Prague-based manufacturer of physical cryptocurrency wallets, has exposed thousands of customers to potential risks. The breach affected approximately 11,742 customers, whose personal details such as names, addresses, phone numbers, and email addresses were compromised. Another 1,947 customers had their name, domicile city, and email address exposed.
The breach occurred due to a shipping provider's security vulnerability, which has been addressed by Trezor. The company stated that it understands the seriousness of the situation and apologized to those affected. The exposure is particularly concerning as it may lead to online or physical attacks on customers.
Cryptocurrency wallets like Trezor do not physically store cryptocurrency tokens but rather access credentials to tokens encoded in a blockchain. Despite being considered secure, recent years have seen an increase in physical attacks targeting wallet holders for extortion purposes.
This breach follows the July exploit of Toronto-based Coinkite's Coldcard crypto wallet, which resulted in the theft of over $100 million in Bitcoin. The exploit was due to a security flaw that generated insecure credentials, which attackers could reproduce.