Skip to content

Trezor vulnerabilities

Trezor appears in our reports concerning a data breach at its logistics provider, ShipMonk, not due to a compromise of its own systems. The incident exposed the personally identifiable information (PII), including names, addresses, and contact details, of roughly 14,000 customers. Defenders should note that while Trezor's hardware and core security remain unaffected, this highlights a significant third-party supply chain risk. The primary concern is the potential use of this leaked data for targeted phishing campaigns aimed at victims to compromise their cryptocurrency assets.

Azərbaycanca: Trezor hesabatlarımızda logistika təchizatçısı olan ShipMonk şirkətində baş verən məlumat pozuntusu ilə əlaqədar görünür. Bu insident nəticəsində təxminən 14,000 müştərinin ad, ünvan, e-poçt və telefon nömrəsi kimi şəxsi identifikasiya məlumatları (PII) ifşa olunub. Müdafiəçilər diqqət etməlidir ki, bu hadisə birbaşa Trezor-un məhsul və ya kibertəhlükəsizlik mexanizmləri ilə bağlı olmayıb, təchizat zəncirindəki üçüncü tərəf riskini nümayiş etdirir. Əsas narahatlıq, ifşa olunmuş bu məlumatların təsirə məruz qalan istifadəçilərə qarşı məqsədyönlü fişinq hücumları üçün istifadə oluna bilməsidir.

This hub is built from skopnix's own reporting on Trezor: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.