The Trezor data breach is bigger than anyone thought. The hardware wallet maker revealed that another 67,000 US customers had their personal details exposed by its shipping provider — nearly five times the original estimate — and scammers now have everything they need to target those users with convincing phishing attacks aimed at their crypto holdings.
By Amir Hassan | September 4, 2026
The Hook: What Just Happened
If you ordered a Trezor hardware wallet from the Czech company between November 2019 and August 2021, your data is likely sitting in a criminal’s spreadsheet right now. Trezor announced the expanded figure in a Friday post on X, citing the latest update from its fulfillment partner, ShipMonk. The exposed records include full names, email addresses, phone numbers, shipping addresses and order details — a complete profile that makes fake “Trezor support” messages terrifyingly believable.
Back in August, Trezor initially estimated that only about 14,000 users were affected by the shipping provider incident. That number has now ballooned to more than 80,000 in total. Importantly, Trezor’s own systems were not compromised — no private keys, no wallet firmware, no seed phrases were touched. This was a third-party logistics leak, not a hack of the vault. But for the people caught in it, that distinction may not matter much.
The Evidence: Why Your Inbox Is the Real Attack Surface
The danger here is not code — it is social engineering, the art of talking you out of your own security. Think of your seed phrase as the master key to your house. A scammer who knows your name, address and exactly which wallet model you bought can call or email pretending to be Trezor, reference your real order, and “helpfully” walk you through a fake recovery process. The moment you read your 12 or 24 words aloud or type them into a website, your funds are gone.
- 67,000 additional US customers affected, on top of the original ~14,000 estimate from August
- Orders from November 2019 to August 2021 are in the exposure window
- Full personal profiles leaked: name, email, phone, shipping address and order specifics
- Trezor wallet security itself was not breached — the leak came from shipping partner ShipMonk
This is not Trezor’s first brush with phishing exposure. In January 2024, the company disclosed that roughly 66,000 users who had contacted its support team since December 2021 were at risk of similar attacks. The pattern is consistent across the industry: blockchain security firm Hacken reported that impersonation-based scams — phishing and social engineering, not code exploits — drove the majority of crypto losses in the first quarter, accounting for about $306 million of the $482 million lost across the industry. In July, a single investor lost nearly $1 million simply by signing a malicious token approval that arrived through a phishing link.
The Core Conflict: Who Is Responsible When a Partner Leaks?
Trezor is pointing the finger squarely at ShipMonk, saying the shipping provider failed to delete customer order data despite written assurances that it would. That is a familiar story in tech: a company promises data deletion, keeps the records on a server anyway, and that server eventually leaks. For a security-focused brand like Trezor, the reputational sting is sharp even if its own cryptography was never at risk. Customers buy hardware wallets precisely because they promise a higher standard of operational discipline.
The episode is a reminder that in crypto your weakest link is rarely the math — it is the human and business processes wrapped around it. Cold storage eliminates the risk of an exchange hack or a malware keylogger, but it cannot stop a scammer from calling your phone with your home address and order history in hand.
Market Implications: What This Means for Your Holdings
Hardware wallets remain one of the best tools for long-term crypto storage, and nothing in this breach changes that. Self-custody — holding your own keys instead of trusting an exchange — is still the gold standard for security-minded investors. But this incident shows that self-custody comes with its own responsibility: you are the last line of defense against social engineering.
The broader market backdrop is turbulent as well. At the time of writing, Bitcoin is trading near $79,800, down about 1.5% over the past 24 hours, with Ethereum around $2,460 and Solana near $102. In an environment where prices are sliding and anxiety is high, users are more vulnerable than usual — scammers time their campaigns to moments of stress, when people are most likely to click “verify my wallet” in a panic.
The Verdict: Three Rules That Will Save Your Crypto
Whether you are among the affected Trezor customers or not, the defense is the same. First, never share your seed phrase with anyone — no legitimate company, including Trezor, will ever ask for it, by email, phone or chat. Second, treat every inbound contact as hostile: do not click links in messages about your wallet order; instead, navigate directly to the company’s official website yourself. Third, verify through official channels only — if a message claims urgency, that urgency is the scam.
A hardware wallet still protects you from remote theft. What it cannot do is stop you from handing over the keys yourself. In 2026, that remains the most expensive mistake in crypto.
Price snapshot at time of writing (CoinGecko, 17:00 UTC): BTC $79,767 (-1.48%), ETH $2,459.75 (-1.38%), SOL $101.84 (-2.63%).
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
67k more people in a phishing spreadsheet because a shipping vendor kept records from 2019. trezor did nothing wrong here but this is why i ship to a po box
^ po box is smart. no real trezor email will ever ask for your seed, burn that into your brain
po box plus a dedicated email for anything crypto related. the moment order history and phone number sit in one spreadsheet you are a phishing target forever
Ordered mine in 2020. Checking my inbox for anything urgent from now on, these seed phrase scams are getting scary convincing.
Bought a Model T in March 2021 so I am probably on that list. The device itself is fine, the leak is names and addresses, the seed never left my hands. That is the design doing its job.
67,000 more people and the root cause was a shipping provider. someone in that fulfillment chain cut corners and now every one of those names is a phishing target
exactly, the coins are safe until you hand the seed over. expect calls from trezor support too, earlier leaks had phone numbers in them
Trezor keeps framing this as a third party problem. You chose that vendor, you collected the customer data. The apology tour writes itself every time.
the design holds until someone reads their seed to a convincing support voice on the phone. the hardware is fine, the humans are the attack surface
bought mine in 2020, checked the affected window, im fine. weird that orders from 2019 are only surfacing now tho
shipmonk sat on name, address, phone and order history for years and nobody flagged it. five times the original estimate, classic slow drip disclosure
ordered two model ones in that window, shipped to an office i left in 2022. at least the stale address buys me a few confused phishing calls lol