Trezor Warns After Data Breach Exposes Addresses of 14,000 Customers
The breach at a third party only affected shipping data; Trezor says the wallets are safe, but it is warning about phishing and misuse of customer data.

Key Takeaways
- Trezor confirms that a third-party data breach exposed the shipping addresses of about 14,000 customers.
- The hardware wallets themselves were not affected, but impacted users face a risk of phishing through email, phone, or mail.
- Trezor says customers were informed by email and that there are no confirmed cases of the leaked data being published or sold.
Trezor has confirmed that a third-party data breach exposed the shipping addresses of about 14,000 customers. According to the company, the hardware wallets themselves were not affected, but impacted users could still become targets of phishing through email, phone, or mail.
What Was Actually Leaked
The maker of cold storage wallets says all affected customers were informed by email. Anyone who did not receive a message, according to Trezor, was not affected by the incident. The company also says it is not aware of any confirmed cases where the leaked data has already been published, shared, or put up for sale.
Customers who bought through Amazon are also outside the group of affected users. According to Trezor, those orders are handled by a separate partner. The company also stresses that its own systems were not compromised and that the devices remain safe.
Why This Risk Still Exists
According to Trezor, the direct damage is not in the wallet itself, but in what criminals can do with the data. With names, addresses, and possibly phone numbers, scammers can pose more convincingly as a bank, crypto exchange, or Trezor itself. That makes targeted phishing campaigns a real risk, even long after a data breach has happened.
That threat is especially sensitive in the crypto sector, because exposed address data can also be misused for physical threats or extortion. Earlier incidents at hardware wallet companies already showed that leaked logistics data later gets reused for scams, fake devices, and other forms of deception.
A Broader Pattern in Hardware Wallets
For Trezor, this is the first time in 13 years that customer numbers and shipping addresses have been exposed, according to the company. At the same time, the maker points out that it has dealt with other third-party incidents before, in 2024 and in 2022, affecting larger numbers of customers.
The case fits a broader pattern in the crypto market: hardware wallets are still technically strong, but the weak spot is often the chain around them, such as support portals, e-commerce partners, and logistics systems. For European crypto users, that highlights how important it is to look not only at the wallet itself, but also at the parties handling customer data.