Trezor shipping provider data breach exposes 13,700 customers' names, emails, phone numbers, and addresses, creating phishing and physical security risks for crypto holders.
Regulation & Gov ·
A data breach at Trezor's shipping provider has compromised personal information for approximately 13,700 recent customers, with roughly 11,700 experiencing exposure of their full names, email addresses, phone numbers, and physical addresses. Binance founder CZ highlighted the incident as evidence of distinct security vulnerabilities in hardware wallet ownership. While Trezor's core systems and private keys remained uncompromised, the leaked data creates a linkage between customer identities and their known possession of crypto hardware, opening pathways for targeted phishing attacks, social engineering attempts, and physical security threats against wallet holders.
CZ used the breach to underscore how different custody approaches carry contrasting risk exposures. Hardware wallets eliminate some software-based attack vectors but introduce a separate vulnerability: once shipment records connect a person's name and home address to their status as a crypto holder, adversaries gain actionable targeting information. The incident underscores tradeoffs inherent in self-custody solutions, where offline key storage solves certain threats while supply chain exposure creates others.
The scope and secondary risks remain partly unresolved. Neither the full timeline of the breach nor the shipping provider's identity has been detailed in available disclosures, and the extent to which stolen records have already been monetized or distributed is unclear.