Trezor Data Breach Raises Serious Security Concerns

Trezor Data Breach Raises Serious Security Concerns
by Mark Gough
By Mark Gough

Trezor is one of the top names in hardware wallets.1

Unlike your typical MetaMask or other app-style self-custody wallet, hardware wallets keep your crypto and your keys safety away from the internet. 

And the hackers that troll it.

That’s why, any time we see an on-chain attack, we’ll remind you about the importance of hardware wallets when it comes to long-term crypto storage. 

My colleague Beth Canova highlights a few different options in her crypto storage breakdown here.

But just because a hardware wallet offers greater protection doesn’t mean it’s out of reach if a bad actor is truly determined. 

In fact, we just received a reminder of exactly that reality. 

Not because the tech failed. But because human error can now come into play. 

Trezor has disclosed a customer-data breach that involves ShipMonk, one of its shipping providers.

We just learned the incident is now considerably larger than first believed.

The original disclosure affected customers in the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.

Specifically, those who received an order in the 90 days before Aug. 8, 2026. 

Trezor initially said 11,742 customers had their full name, email address, phone number and shipping address exposed.

It also said another 1,947 customers had partial information compromised.

However, Trezor updated its disclosure on Sept. 4.

Source: Trezor.2

 

This was after ShipMonk informed the company that it was still holding older customer-order data dating from November 2019 to August 2021. 

Trezor says it had repeatedly received written confirmation that this information had previously been deleted.

Those newly discovered records affect about 67,000 more U.S. customers. 

The exposed information includes names, email addresses, phone numbers, shipping addresses and order numbers.

Trezor says its wallets, devices and internal systems were not compromised. 

Nor did the leaked data include private keys or wallet backups.

Still, that does not make this breach harmless.

For crypto holders, this is particularly sensitive information for two big reasons.

  • It reveals that they purchased a hardware wallet.
  • This data can identify someone by name and home address.

In other words, whoever has access to this data can assume there will eventually be crypto stored in that wallet. 

They can also assume to know where they can find that wallet.

This gives criminals far more information than they would get from an ordinary email-address leak.

The immediate danger, however, is targeted phishing and social engineering. 

Criminals could contact affected customers by email, phone, letter, or even in person, appearing more convincing because they already know their name, address, and that they bought a Trezor device.

There is also a physical-security angle here that crypto investors should not ignore. 

A database of people known to have purchased hardware wallets could potentially be used to identify higher-value crypto holders for physical targeting.

We’ve discussed the growing risk these so-called “$5 wrench attacks” before. 

 

Last month’s Coldcard hack was just one of many situations where criminals bypassed cybersecurity altogether and tried to force someone to hand over access to their crypto. 

A leak like this could give criminals all the data they need to help them identify potential targets.

To its credit, Trezor quickly posted ways to avoid a scam.

Source: Trezor on X.3

 

If you have ever purchased a Trezor device, be extremely suspicious of any unsolicited email, phone call or letter.

Also be on high alert if someone arrives at your home claiming to represent Trezor, an exchange or another crypto company.

A few more suggestions …

  • Never enter your seed phrase or wallet backup on a website.
  • Never disclose it over the phone or by email.
  • And never give it to anyone under any circumstances. 

Remember, too, that Juan Villaverde, Marija Matić and I — or anyone else on the Weiss team — will ever contact you for this kind of sensitive data.

Be sure to visit our Online Fraud portal on the Weiss website for ways to stay safe and report potential scams. 

Verify any communication about your wallet independently through Trezor’s own official channels.

Stay safe out there! 

Best, 

Mark Gough

P.S. There’s one more thing you should secure before the long Labor Day weekend. That is, your spot at an urgent Tuesday briefing about a coming tech disruption. 

The military, defense contractors and every U.S. federal agency will soon be required by law to implement this solution. 

In the aftermath of the Trezor breach, you’ll want to save your spot here and see how you can get in on the ground floor.


1 https://bitcoinfoundation.org/news/analysis/best-crypto-wallets/

2 https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident

3 https://x.com/trezor

About the Contributor

Mark Gough has spent over a decade in crypto and traditional markets. His specialty is to spot small crypto innovators with big profit potential and solid staying power. Mark was an early (Series A) investor in multiple blockchain projects. He was a seed investor in Render long before it became a crypto AI leader.

Crypto
See All »
B
B
ETH $2,480.50
B
B
B
B
B
SOL $103.97
B
S $0.03
B
B
SUI $0.80
B
TRX $0.33
B
ZEC $1,026.40
Crypto Ratings
Loading...