Trezor hardware wallet company disclosed a data breach.
Regulation & Gov ·
A shipping partner's security failure has exposed personal information belonging to thousands of Trezor customers. The breach affected 11,742 customers with complete data exposure and 1,947 with partial exposure across seven countries—the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal—among those who placed orders in the 90 days prior to August 8th, 2026. Compromised details include full names, shipping addresses, phone numbers, and email addresses, though in partial cases only name, city, and email were exposed.
Trezor disclosed the incident after a third-party logistics provider experienced a breach of order data. The company's strict 90-day data retention policy, which it extended to fulfillment partners, limited the scope of exposed records. According to Trezor's statement, all affected users have been notified separately by email, and the company emphasized that its own systems and hardware devices remain secure.
The breach carries operational risks despite the hardware wallet platform itself remaining uncompromised. Trezor warned customers to expect increased phishing attempts and reiterated standard security practices: never enter recovery seeds on websites and only obtain software updates through official channels. The company is investigating the incident further, though the identity of the specific shipping provider has not been publicly confirmed.