Trezor breach balloons sixfold after ‘deleted’ shipping logs resurface
What happened?
Hardware-wallet maker Trezor originally reported a breach that affected roughly 13,689 customers. A later update revealed that an additional batch of about 67,000 U.S. orders — stretching from November 2019 through August 2021 — were also left sitting in a logistics vendor’s systems even after written promises to delete them. Trezor hasn’t published a single combined total, but the two disclosed groups suggest somewhere in the ballpark of 80,000 affected records.
The exposed fields are neither glamorous nor cryptographic — names, email addresses, phone numbers, shipping addresses and order numbers. Still, those details can link a real person and their address to a hardware-wallet purchase, which is a different kind of privacy ouch compared with a plain old email leak.
According to reporting around the incident, the vendor flagged a vulnerability in an analytics tool as the route of unauthorized access. That zero-day could let an attacker create an admin-like session and download tables in bulk, which is how the historical order data was apparently pulled. Trezor says the breach did not touch its wallet systems: recovery seeds, private keys and funds were not exposed.
Why it matters — and what you should do
So why lose sleep? Because this isn’t about stolen crypto keys — it’s about a breadcrumb trail. With names, addresses and purchase records in someone else’s hands, scammers can craft very believable phishing emails, make fraudulent phone calls, send bogus mail, or even try something more physical. Trezor warned these are plausible risks though it didn’t point to any confirmed follow-on attacks yet.
If you’re on the list, Trezor says it emailed people directly; if you didn’t get a notice, you were probably not affected. Regardless, basic paranoia is healthy here: never share your wallet recovery or backups, don’t enter them into websites, and treat unexpected messages about your device or order with extreme suspicion.
Practical steps: watch for phishing or unusual calls, enable strong protections on your email (like two-factor auth), and verify any outreach before handing over info. If someone shows up claiming to be from a delivery company with odd instructions, slow down and confirm — scammers love to use urgency as a trick.
The bigger lesson is organizational: a deletion policy is only useful if partners actually follow it. Trezor’s policy required erasing delivery data after 90 days, but written assurances from the fulfillment vendor didn’t stop old records from lingering. If you care about privacy, vendor audits and verified deletion matter as much as the tech that protects your keys.
Short version: your hardware wallet is still doing its job keeping keys safe, but the paper trail of the purchase can be a separate privacy weak spot. Stay alert, don’t share seeds, and treat unexpected messages like suspicious party invitations — decline, verify, and then maybe laugh about it later.
