1

When Your Hardware Wallet Order Betrays Your Home: Trezor Fulfillment Leak

What went down

Short version: a fulfillment partner that ships Trezor hardware wallets had a bad day. In early August, the company handling deliveries told Trezor it had been accessed by an unauthorized actor. Roughly 13,689 customers’ records were involved, and about 11,742 of those included full delivery addresses. Another 1,947 records included names, cities and emails but not full addresses.

Trezor says its own networks, products and wallet software were not hacked — the compromise happened at the third-party shipping side. That’s important: your seed phrase and private keys weren’t leaked. What did leak, though, was the link between real people (and their homes) and the fact they ordered a device meant to protect crypto.

The affected orders span a few months, with the fully exposed deliveries falling between May 10 and August 8. The shipper is normally supposed to delete or anonymize order info within 90 days of delivery, which is meant to limit how long this sort of data sticks around. In this case, that process clearly didn’t work as it should have.

Why this is dangerously awkward — and what you can actually do about it

On its face this isn’t a wallet-hack: attackers don’t suddenly have your private keys. But it’s way more useful intel than a random email scrape. Knowing someone bought a hardware wallet and where they live turns basic scams into laser-targeted social engineering — emails, convincing phone calls, spoofed messages, or even letters that reference the purchase to build trust.

There’s an even darker path: criminals can use delivery data to identify likely crypto holders for physical theft or burglaries. Law enforcement cases from recent years show networks have used stolen customer lists to find targets and coordinate in-person attacks. Industry data also shows that violent crypto theft has been growing — millions lost to home invasions and similar crimes, with home break-ins making up a rising share of incidents year over year.

So what should you do if you were affected — or just want to be safer? A few practical, mildly annoying but effective moves:

– Treat any urgent-sounding messages about your wallet or account as suspicious. Scammers will use personalization to sound legit. Verify through official channels before responding.
– Never share your seed phrase or type it into a website. Ever. No amount of pressure is worth it.
– Use separate email aliases for different services, unique passwords, and a password manager. Don’t rely on SMS for account recovery; use hardware-based multi-factor authentication instead where possible.
– If you expect sensitive deliveries, consider rerouting to a locker, workplace, or other non-residential pickup to avoid linking purchases to your home.
– For truly significant holdings, don’t rely on a single hardware device. Multi-signature setups are a stronger model: stealing one device shouldn’t give anyone everything.

On the company side, Trezor plans to reduce shipping risk with an “anonymous delivery” option — neutral packaging, locker pickup, generic sender info and automatic deletion of shipping IDs — rolling out in the EU by September 2026 and in the US later in the year. That sort of operational change can help, but it’s not a silver bullet; data hygiene and vendor oversight matter a lot.

Bottom line: your keys may be safe for now, but your privacy and physical safety can be undermined by someone else’s sloppy data handling. Keep your guard up, split up risk where you can, and treat unexpected outreach like it could be a scam — because often, it will be.