Trezor has just warned 13,689 customers after a data leak at one of its logistics providers. Names, emails, phone numbers and delivery addresses were exposed according to the users affected. The wallets were not hacked and no private keys were leaked. So good news for cryptos. A little less for personal data.

In brief
- 13,689 Trezor customers are affected by the leak.
- No private keys or recovery phrases have been compromised.
- Trezor is now working on an anonymous delivery option.
Trezor confirms leak of 13,689 customers
The incident did not come directly from Trezor. It concerns a service provider used for shipping its hardware wallets. The manufacturer had already warned its users against fake support emails. 11,742 customers are most exposed. Their names, delivery addresses, emails and phone numbers are found in the compromised data.
For 1,947 other people, the leak concerns only the name and email address. Total: 13,689. Affected customers are located in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor specifies that the affected orders date back to the 90 days preceding August 8.
The manufacturer especially emphasizes what has not leaked. No wallet backup, no recovery phrase and no private key appear in the data concerned. Trezor devices therefore remain secure.
It’s not a detail. A person who collects a name, email and address cannot directly move bitcoins or other cryptos stored on the wallet. However, she has enough information to prepare something else.
Phishing becomes the main risk in crypto
Owners of hardware wallets are attractive targets for fraudsters. They already own cryptos and value their security enough to invest in a specialized device.
With an email address, a hacker can send a fake Trezor message. With the name and telephone number, he can personalize his approach. And with the delivery address, he also knows where the wallet was sent. The attempt immediately becomes more credible.
The sector already knows this scenario. Ledger customers were targeted by phishing after a leak linked to the service provider Global-e.
Scammers usually seek to recover the recovery phrase. Fake technical support, false urgent update, imaginary problem on the wallet: there is no shortage of excuses. Trezor therefore reminds us of a simple rule. The company never asks for a customer’s backup wallet.
There is also the physical address. It does not allow any computer attack against the wallet, but it potentially reveals the home of a person who owns cryptos. Not ideal. Trezor is now investigating with the affected service provider and directly contacting customers whose information was exposed.
Trezor wants to make its deliveries more anonymous
This leak shows above all that the security of a hardware wallet does not stop at the hardware wallet. The device can be perfectly protected. You still have to order it, pay for it, ship it and have it arrive somewhere. Several companies can intervene between purchase and delivery.
Trezor claims to have imposed data retention rules on its partners. The incident occurred despite these precautions.
The manufacturer is now working on a function called “Anonymous Delivery”. The principle should help reduce the personal information needed to receive a device. Trezor has not yet fully detailed how it works.
The idea comes at the right time. Wallet manufacturers are regularly faced with problems affecting services located around their products. Ledger and Trust Wallet have also experienced several security incidents. The 13,689 Trezor customers did not lose their cryptos. That’s the main thing. However, they will have to watch their next emails and text messages a little more carefully. The fraudsters did not get their keys. They got enough to try and get them to give it to them.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
