Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › Trezor warns 14,000 customers after fulfilment partner suffers data breach
Business

Trezor warns 14,000 customers after fulfilment partner suffers data breach

By Diego Whitfield · · 2 min read

Hardware wallet maker Trezor has notified roughly 14,000 customers that their personal information may have been compromised after one of the company's fulfilment partners experienced a data breach, marking the first known incident in which Trezor users' physical shipping addresses were exposed.

What Happened

Trezor, a well-known manufacturer of cold-storage devices used to secure cryptocurrency, alerted affected customers after a third-party responsible for order fulfilment suffered a security incident. The breach exposed shipping details tied to customer orders, a category of data that had not been compromised in previous Trezor-related incidents.

The company stressed that the breach occurred at the partner level rather than within Trezor's own core systems. Importantly, the exposed data does not include recovery seeds, private keys, or PINs — the sensitive information that would allow an attacker to directly access a user's funds.

Physical addresses were exposed for the first time, raising fresh concerns about targeted phishing and real-world risks for crypto holders.

Why It Matters

While shipping addresses may seem less critical than wallet credentials, security experts have long warned that exposing the physical locations of hardware wallet owners creates real dangers. Individuals known to own crypto-securing devices can become targets for phishing campaigns, social engineering, or even physical threats.

Trezor has repeatedly cautioned its user base to remain vigilant against scams that impersonate the company. Attackers armed with names and addresses could craft convincing fraudulent communications designed to trick recipients into revealing their recovery phrases or installing malicious software.

Customers who received the notification are being urged to take precautions, including:

  • Treating unsolicited messages claiming to be from Trezor with suspicion
  • Never sharing recovery seeds or PINs with anyone
  • Verifying communications through official channels before acting

The incident underscores an ongoing challenge for crypto firms: even companies with strong internal security practices remain vulnerable through the third-party vendors and partners that handle logistics, support, and order processing.

Was this useful?👍 Yes👎 No