09/08/2026
If you bought a Trezor between November 2019 and August 2021, assume your name, email, phone number, and home address are in criminal hands.
Trezor says a breach at its shipping provider exposed data for about 67,000 more US customers than first reported. Trezor's own systems were not compromised, but that distinction does not help you much. Attackers now know you own a hardware wallet and where you live.
What to expect and how to respond:
1. Emails or texts claiming a "security update," "firmware issue," or "breach response" that ask you to enter your recovery seed. No legitimate wallet company will ever ask for it.
2. Physical mail or unsolicited replacement devices. Only use hardware bought directly from the manufacturer.
3. Phone calls from "support" that already know your order details. Knowing your data is not proof of identity. Hang up and go to the official site yourself.
Your seed phrase stays offline and stays private. If you have already entered it somewhere and funds have moved, act fast: document everything, file a report with law enforcement, and get tracing started while the trail is fresh. Speed matters more than anything else after a theft.
Original report: https://cointelegraph.com/news/trezor-data-breach-affects-67k-us-customers