Trezor's Data Breach Expands: 67,000 Additional Customers Caught in Widening Security Failure
The Trezor hardware wallet incident just got worse. We're now looking at 67,000 more customers exposed than initially disclosed, and the timeline reveals something particularly damning: some compromised records stretch back to 2019—years past the 90-day data retention window that Trezor claims its

The Trezor hardware wallet incident just got worse. We're now looking at 67,000 more customers exposed than initially disclosed, and the timeline reveals something particularly damning: some compromised records stretch back to 2019—years past the 90-day data retention window that Trezor claims its partners agreed to honor.
This isn't a minor update to an already-contained situation. This is a fundamental breakdown in how Trezor managed customer data across its partner ecosystem.
The Retention Problem
Here's where it gets ugly for the crypto custody space. Trezor established clear contractual agreements with third-party partners stating they'd delete customer records within 90 days. Simple enough. Except someone didn't follow the script—or worse, Trezor never enforced it.
Finding data from 2019 in a 2024 breach means records sat in partners' systems for up to five years. That's not a minor compliance slip. That's negligent data hygiene on a scale that should concern anyone holding crypto or relying on hardware wallets for security.
The implications ripple across the entire portfolio management landscape. If Trezor couldn't monitor what its partners were doing with customer information, what does that say about transparency in the crypto hardware wallet market? This directly impacts how traders and long-term hodlers should evaluate custody solutions.
What This Means for the Crypto Market
The expanding breach creates a wider surface area for attacks. More customer records means more potential targets, more email addresses tied to crypto holdings, and more ammunition for sophisticated phishing campaigns targeting the crypto community. This is especially dangerous in a market where social engineering often precedes exchange hacks or portfolio raids.
From a market intelligence perspective, this signals deeper governance issues within Trezor's operations. The fact that they're discovering additional breach scope weeks or months after the initial incident suggests their forensic investigation was incomplete—or their data mapping was so poor they didn't even know what was exposed initially.
The Crypto Custody Reckoning
We're watching the hardware wallet space face real accountability for the first time. Trezor's mishap forces the entire industry to answer hard questions: How are partners actually storing customer data? Who's auditing retention policies? What's the actual chain of custody for sensitive information in the crypto ecosystem?
For traders building diversified portfolios, this is a wake-up call about due diligence beyond just evaluating which wallet offers the best features or security theater. The operational maturity of custody providers matters as much as their cryptographic protocols.
Alpha Take
The expanded breach reveals systemic failures in Trezor's partner oversight and data governance—critical vulnerabilities that extend beyond this incident. Crypto investors need to audit their own exposure and consider whether their custody strategy properly accounts for third-party risk. This incident should accelerate the market's demand for transparent, audited data retention practices from all major wallet providers and custodians.
Originally reported by
Decrypt
Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.