Trezor Discloses Third-Party Shipping Provider Data Breach Affecting Over 13,600 Customers
Key Takeaways
- •Approximately 13,689 Trezor customers were affected by a data breach at a third-party shipping provider, with 11,742 having full personal information exposed and 1,947 having partial data compromised.
- •The breach was limited to the external shipping provider's data and did not impact Trezor's internal systems, hardware wallets, private keys, or any cryptocurrency assets.
- •The exposed customer details—including names, physical addresses, phone numbers, and emails—could enable highly targeted phishing campaigns leveraging victims' known hardware wallet ownership.
- •Trezor is continuing to notify affected users and coordinating with the shipping provider while urging customers to verify all communications through official channels and never share recovery phrases.
- •The incident echoes a similar 2020 breach at competitor Ledger that affected roughly 270,000 customers and led to widespread phishing attacks and physical threats against users.

Hardware wallet manufacturer Trezor has disclosed a data breach involving one of its third-party shipping providers that exposed the personal information of thousands of customers.
According to the company, the incident affected 11,742 customers whose full names, addresses, phone numbers, and email addresses were exposed. An additional 1,947 customers had partial data compromised, bringing the total number of affected individuals to approximately 13,689.
The breach was confined to information held by the external shipping provider and did not involve Trezor's internal systems. Trezor, produced by Czech-based SatoshiLabs, is one of the most widely recognized hardware wallet brands in the cryptocurrency industry, alongside competitors such as Ledger. The incident highlights a persistent challenge for hardware wallet vendors: while the devices themselves are designed to keep private keys offline and secure, the logistics chain required to physically deliver them introduces a separate attack surface that falls outside the manufacturer's direct control.
Systems and Devices Remain Secure
Trezor emphasized that its systems, hardware wallets, and customer devices remain secure, stating that the incident did not compromise wallet security or private keys.
No cryptocurrency assets were reported stolen as a result of the breach. However, the exposed personal information could increase the risk of phishing attempts and other social engineering attacks targeting affected customers. The combination of names, physical addresses, phone numbers, and email addresses is particularly sensitive in the cryptocurrency context, as it could enable highly targeted phishing campaigns or impersonation attempts that leverage the victim's known ownership of a hardware wallet.
The company is expected to continue notifying impacted users and coordinating with the shipping provider as the investigation progresses.
Customers Urged to Stay Vigilant
The breach underscores the risks associated with third-party service providers in the cryptocurrency industry. It is not the first time a major hardware wallet maker has faced a data exposure incident; competitor Ledger experienced a significant e-commerce database breach in 2020 that affected approximately 270,000 customers and led to widespread phishing campaigns and reports of physical threats against affected users. That incident prompted industry-wide discussions about data minimization and the handling of customer information in hardware wallet fulfillment processes.
Customers affected by the Trezor incident should remain cautious of unsolicited emails, phone calls, or messages requesting sensitive information or wallet recovery details.
As the investigation continues, users are encouraged to verify any communications directly with Trezor through official channels and to avoid sharing recovery phrases or private keys under any circumstances.