Loading market data...

Trezor Shipping Partner Breach Exposes Data of 13,689 Customers

Trezor Shipping Partner Breach Exposes Data of 13,689 Customers

Trezor, the hardware wallet maker, said a data breach at its shipping partner exposed personal information belonging to 13,689 customers. Names, contact details, and delivery addresses were among the data taken. The company stressed that the wallets themselves were not compromised.

What the breach exposed

The affected records included customer names, phone numbers or email addresses, and the physical addresses where Trezor devices were shipped. The company did not specify which shipping partner was involved or how the intruders got in. It also didn't say when the breach happened or how long it went undetected.

Trezor's statement focused on the scope: 13,689 customers. That's a relatively small slice of its user base, but the data is the kind that fuels phishing scams and identity theft. Delivery addresses, in particular, are sensitive for people who buy hardware wallets to keep their crypto holdings private.

Wallets stay secure

The company was explicit that the breach did not touch the wallets themselves. Trezor devices store private keys offline, and the exposed data was limited to shipping records. No funds were at risk from this incident, according to the company.

Still, the breach is a reminder that the supply chain around crypto hardware can be a weak point. A shipping partner holding customer data is a target, even if the core product is built to resist attacks.

What customers should watch for

Trezor advised affected users to be on guard for phishing emails or phone calls that reference their recent orders. Scammers often use stolen shipping details to make their messages look legitimate. The company said it would contact affected customers directly with more information.

For now, the key question is how the shipping partner's systems were breached and whether other companies using the same partner are also exposed. Trezor hasn't named the partner, so customers can't easily assess the broader risk.

The company said it is working with the partner and relevant authorities to investigate. It didn't offer a timeline for when the investigation might conclude or whether it would release more details.