Hardware wallet maker Trezor is grappling with a widening data breach that has now exposed the personal information of roughly 67,000 additional customers, with some of the compromised records dating back to 2019 — far beyond the 90-day data retention window the company said its partners had committed to.
A Breach That Keeps Growing
The latest disclosure marks an expansion of a security incident that has steadily pulled in more Trezor customers than initially believed. The newly affected 67,000 users add to earlier tallies, underscoring that the scope of the compromise was larger than first reported.
The exposed data appears to have originated not from Trezor's core systems but through third-party partners handling customer support and related services. That distinction matters little to affected users, whose personal details are now potentially in the hands of malicious actors.
Records dating back to 2019 surfaced in the breach — years beyond the 90-day retention limit Trezor's partners were supposed to honor.
Retention Promises Under Scrutiny
Perhaps the most troubling revelation is the age of some of the leaked records. Trezor had stated that its partners agreed to purge customer data after 90 days, yet information stretching back roughly six years was found among the exposed material. That gap raises serious questions about how closely the company monitored its vendors' data-handling practices.
For a company whose entire value proposition rests on securing users' crypto assets through cold storage, a lapse in safeguarding customer contact information is especially damaging to trust. Hardware wallets are marketed as the gold standard for keeping funds offline and out of reach of hackers.
Security experts have long warned that exposed customer data — even when it doesn't include private keys or seed phrases — can fuel targeted phishing campaigns. Attackers often use verified email addresses and names to craft convincing scams aimed at tricking wallet owners into surrendering their recovery credentials.
What Users Should Watch For
Trezor customers, particularly those who interacted with the company or its partners in recent years, should treat any unsolicited communication with heightened suspicion. The company has repeatedly stressed that it will never ask users for their recovery seed.
- Be wary of emails or messages claiming to be from Trezor support
- Never share your recovery seed or PIN under any circumstances
- Verify the authenticity of any communication before acting on it
The incident serves as a reminder that even security-focused firms remain vulnerable through their supply chains, and that data retention policies are
