Cryptocurrency hardware wallet manufacturer Trezor has acknowledged that a security incident at one of its logistics providers compromised the personal information of more than 13,000 buyers, according to a company advisory published this week. While the company's initial assessment indicated the compromise affected only recent purchases within a 90-day window, updated information suggests orders from earlier periods may also have been impacted. The incident underscores how even companies marketing secure, offline hardware can fall victim to vulnerabilities in their supply chain.
The breach exposed names, email addresses, phone numbers, and shipping addresses for 11,742 buyers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who purchased Trezor products between May 10 and August 8, the company disclosed. Another 1,947 buyers had their names, home cities, and email addresses compromised, with some members of this group potentially having ordered before May 10. ShipMonk, Trezor's logistics partner responsible for storing and shipping products, is the source of the breach. The third-party provider is bound by Trezor's 90-day retention policy, which mandates that partners delete or anonymize buyer information within 90 days of collection.
While Trezor reassured buyers that its own systems and devices haven't been compromised, the company cautioned that "affected customers could experience an increase in phishing attempts." The exposed information could enable criminals to create persuasive phishing attacks masquerading as banks, cryptocurrency exchanges, or Trezor itself. The company reached out to impacted buyers directly and urged them to verify any communications against details shared through its official channels. "This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses," the company stated, adding it is "deeply sorry to those affected."
The incident has prompted Trezor to accelerate development of an "Anonymous Delivery" option, which the company described as its "top priority" project in a social media update separate from the main advisory. Buyers using the service will complete checkout without connecting their home address or real-world identity to a purchase, instead providing a nickname or label identifier and receiving products at automated delivery lockers in unbranded packaging with generic sender labels. Carriers will communicate only through email or SMS to transmit a PIN for the locker. Trezor said the service is targeting a September rollout in the European Union and a year-end launch in the United States. Meanwhile, competitor Cake Wallet seized on the breach to promote an alternative approach, suggesting crypto holders use an old smartphone with its wallet software installed because "there is no order, no shipping address, or customer data tied to the purchase." The episode illustrates how third-party logistics relationships create persistent exposure points that hardware security features alone can't eliminate, forcing companies to rethink whether traditional e-commerce fulfillment models align with their customers' privacy expectations.

