NewsCryptoTrezor Data Breach Exposes Information of Nearly 14,000 Hardware Wallet Customers

Trezor Data Breach Exposes Information of Nearly 14,000 Hardware Wallet Customers

Author: Bitcoin Magazine·

Key Takeaways

  • Trezor disclosed a data breach affecting 13,689 customers across seven countries who received orders within 90 days prior to August 8.
  • The breach originated at ShipMonk, Trezor's third-party fulfillment partner, through unauthorized access to systems containing customer data.
  • Approximately 11,742 customers had their names, emails, phone numbers, and shipping addresses compromised, while 1,947 had only names, cities, and emails exposed.
  • Trezor confirmed its own systems and devices remain secure but warned affected customers to expect increased phishing attempts.
  • The incident follows other major security breaches in the hardware wallet industry, including Ledger's 2020 breach and a recent attack on Coinkite's Coldcard wallets estimated at over $130 million in stolen Bitcoin.
Trezor Data Breach Exposes Information of Nearly 14,000 Hardware Wallet Customers

Hardware wallet manufacturer Trezor has disclosed a data breach affecting 13,689 customers across seven countries, the company announced Thursday.

In a statement posted on X, Trezor said that customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within 90 days prior to August 8 were impacted by the incident.

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…

— Trezor (@Trezor) August 13, 2026

"Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts," the Prague, Czech Republic-based company said. "We are deeply sorry to the community and those affected."

The concern is particularly acute for hardware wallet users because cryptocurrency transactions are irreversible — unlike traditional banking, there is no chargeback or fraud department to reverse a transfer once funds are sent. Attackers who obtain a customer's name, address, and purchase history can craft highly targeted schemes, such as fake replacement-device offers or impersonation of Trezor support, designed to trick users into exposing their recovery seed phrase.

According to Trezor, 11,742 customers had their names, emails, phone numbers, and shipping addresses compromised. A further 1,947 customers had only their names, cities, and emails exposed.

SatoshiLabs, Trezor's parent company, confirmed in an email to Bitcoin Magazine that its third-party fulfillment partner, ShipMonk, experienced "unauthorized access to their systems containing customer data." The incident underscores a structural tension in the hardware wallet industry: companies that champion self-custody and privacy still depend on traditional e-commerce infrastructure — shipping providers, fulfillment centers, and payment processors — that collect and store customer data outside the user's control.

"Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor," the company warned.

SatoshiLabs said it is continuing to investigate the incident.

Trezor is one of the most widely used Bitcoin hardware wallet solutions and also supports storage of other cryptocurrencies.

The breach follows a series of security incidents targeting cryptocurrency hardware wallet users. In 2020, an unauthorized party accessed competitor Ledger's e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers. That breach led to a wave of phishing attacks and extortion attempts that persisted for years. Earlier this year, customers reported receiving notifications from Global-e, Ledger's payment partner, that a data breach at its cloud systems had also leaked sensitive customer data.

More recently, the Bitcoin community was rocked by an attack on Canadian company Coinkite's Coldcard hardware wallets. Hackers began draining funds at the end of last month, with initial estimates of $111 million in Bitcoin stolen. As investigations continue, some estimates place the total figure above $130 million. The theft prompted both individual Bitcoiners and Coinkite to urge users to move their funds as attackers continued targeting devices.

This article first appeared on Bitcoin Magazine, written by Mathew Di Salvo.