Trezor disclosed that a data breach at its shipping provider exposed the full names, email addresses, phone numbers and physical addresses of 11,742 recent customers, though the hardware wallet's systems and private keys remained secure. The breach affected approximately 13,689 customers overall, with the remaining users having partial information compromised.

The exposure links user identities directly to known cryptocurrency holders and their home locations, creating vectors for phishing, social engineering and physical security attacks that hardware wallet providers have long advertised as mitigated against. Binance founder CZ said on X the incident illustrates a fundamental difference in risk profiles between hardware wallets and software self-custody solutions, where offline key storage protects the cryptographic material but not the customer data surrounding it.

Trezor's announcement on August 13 identified the compromised vendor as a third-party logistics partner responsible for shipping devices. The company said its own infrastructure was not breached. Trezor advised affected users to be cautious of unsolicited contact claiming to be from the company and to verify any communications through official channels.

MSB Intel

Hardware wallet manufacturers have built their security narrative on the principle that private keys never leave the device, making the wallet itself resistant to remote compromise. The Trezor breach preserves that core claim while exposing a perimeter risk: users who order a hardware wallet create a paper trail linking their identity to their intention to hold cryptocurrency in a specific location. A seller with access to shipping manifests gains addressable targets for thieves or scammers seeking to exploit cryptocurrency owners.

CZ's public commentary on the breach framed it as illustrative of hardware wallet risk profiles rather than as a contained vendor failure. Binance has long promoted its own custody solutions and third-party hardware partners while also warning users of the security trade-offs inherent in different custody models.

The 11,742 users with full exposure represent 85.7 percent of the total affected customers, concentrating the highest-risk segment. Trezor did not disclose whether the breach included transaction history, account recovery information or other sensitive metadata beyond the four core data points. The company is investigating whether additional information was accessed and said it would provide updates as the investigation concluded.