Trezor Data Breach Exposes Shipping Details of 13,689 Customers

Share:
Trezor reported a shipping-provider data breach that exposed order information for 13,689 customers who received orders within 90 days before August 8, 2026, including 11,742 with full exposure of name, email, phone and shipping address and 1,947 with partial exposure. The company says its hardware wallet devices and systems were not compromised, has contacted affected users, warned of heightened phishing risk, cited a 90 days data retention policy that limited exposure, and is accelerating an Anonymous Delivery privacy option for the EU in September and the US by end of 2026 to reduce identity linkage and improve crypto security and privacy.
A hardware wallet company has a rather unpleasant reminder that protecting crypto users does not stop at the blockchain. Trezor says a data breach at one of its shipping providers exposed sensitive order information belonging to 13,689 customers across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Shipping Breach Exposed Names, Addresses And Contacts
The breach affected new customers who received an order within the 90 days before August 8, 2026. Trezor said 11,742 customers suffered full exposure, including their name, email, phone number and shipping address, while another 1,947 had partial exposure involving their name, city and email.
The company says its own systems and devices remain secure. Still, exposed contact and address information creates an obvious problem, phishing. Trezor has warned affected customers to expect potentially increased attempts to trick them into revealing sensitive wallet information.
Trezor Says Its Short Data Retention Limited Damage

There is at least one limiting factor. Trezor said its strict 90 days data storage policy also applies to its fulfillment partners, restricting how much historical customer information was available when the breach occurred.
All affected customers have reportedly been contacted separately by email. The company is investigating the incident and says further updates will be published through its blog.
The warning to users is blunt and important, never enter a wallet backup on a website or share it with anyone, regardless of how convincing a message looks.
Anonymous Delivery Is Trezor’s Next Privacy Push
Trezor is also accelerating an Anonymous Delivery option, which it aims to launch in September for the EU and by the end of 2026 for the US.
The planned service would use a dedicated checkout, nickname or label ID, automated parcel lockers and unbranded packaging with generic sender information. For Trezor customers, the idea is simple, buying a hardware wallet should not necessarily create a direct trail to a home address or real world identity.
Trezor data breach concerns may have exposed shipping information, but the company’s proposed Anonymous Delivery system shows where it wants to go next.
Read More

