Trezor Exposes Data of 13,689 Customers Through Shipping Partner Breach
A third-party shipping provider used by Trezor was compromised, exposing personal data for roughly 13,689 customers across seven countries. The hardware wallet devices themselves and seed phrase backups were not affected, but the exposed shipping records create a phishing target pool.
Trezor Exposes Data of 13,689 Customers Through Shipping Partner Breach
A shipping provider used by Trezor was compromised, exposing personal data for roughly 13,689 customers across seven countries. Trezor disclosed the incident on Thursday. The hardware wallet devices themselves, along with seed phrase backups, were not touched.
The breach sits entirely outside Trezor's core infrastructure. An attacker gained access to customer records held by a third-party logistics partner, pulling names, addresses, and contact details for affected users. Trezor has not publicly named the shipping provider. The exposed data does not include private keys, wallet credentials, or recovery phrases, which means no funds are at direct risk from the breach itself.
That distinction matters, but it does not make the exposure benign. Shipping records for hardware wallet buyers are high-value targeting data. Anyone on that list is, by definition, someone who spent money on dedicated crypto security hardware, which signals meaningful holdings. Attackers with a list of 13,689 confirmed hardware wallet owners have a ready-made phishing target pool. Expect impersonation emails purporting to be from Trezor support, fake firmware update alerts, and SMS lures referencing the breach itself. The window between disclosure and the first phishing wave is typically short.
Supply chain exposure is a recurring weak point in crypto hardware distribution. Trezor suffered a separate incident in 2022 when a third-party support portal was compromised, leaking approximately 66,000 customer email addresses and phone numbers. That breach similarly left devices unaffected but generated months of targeted phishing campaigns against the exposed users. The current incident is smaller by count but covers seven countries, suggesting international distribution channels were involved. Third-party vendor risk has consistently been the harder problem for hardware wallet makers to solve: the device security can be near-airtight while the surrounding logistics chain remains a soft target.
Trezor's proactive disclosure on the day of publication is the right call and limits some reputational damage. Companies that sit on breach notifications, as has happened repeatedly across the broader tech sector, tend to face far harsher user backlash when the delay comes to light. Trezor notifying affected customers directly gives those users a chance to tighten their defenses before phishing attempts arrive.
For affected customers, the immediate steps are straightforward: treat any incoming communication claiming to be from Trezor with heightened skepticism, verify firmware updates only through the official Trezor Suite application, and never enter a seed phrase in response to any prompt, regardless of how legitimate it appears. Trezor will never ask for a recovery seed. Any message that does is an attack.
The broader takeaway for the hardware wallet market is structural. Device-level security in this product category has matured significantly. Trezor, Ledger, and their competitors have invested heavily in tamper-resistant chips, open-source firmware, and physical attack mitigations. The perimeter that remains porous is everything outside the device: the support systems, the shipping partners, the marketing databases. Until manufacturers apply the same scrutiny to third-party vendors that they apply to silicon, customer metadata will keep leaking even when private keys do not.
Trezor has not disclosed whether the affected customers have been individually notified or what remediation, if any, the company is offering. No regulatory body has been named in connection with the disclosure.





