Trezor said its own systems were not compromised and that its devices remain secure. All affected customers were contacted separately by email, according to the company; its notice says customers who did not receive an email from help@trezor.io were not affected.
The company warned recipients to expect more sophisticated phishing attempts and said scammers could use the information for fake emails, phone calls and letters, or to impersonate Trezor, a bank or a crypto exchange. It told customers never to enter their wallet backup on a website or share it with anyone, and to verify messages against Trezor's official channels.
Physical-Security Risk
The exposed records identify people who recently received an order from Trezor and, for most of those affected, include the address where it was delivered. That combination can make a fake support message more convincing and could also help a criminal select a physical target.
A public repository maintained by Jameson Lopp lists known physical attacks against bitcoin and crypto owners dating back to 2014, including home invasions, kidnappings, robberies and extortion. Trezor's disclosure describes a potential risk; it did not report a compromise of its systems or devices.
Retention Policy Limited the Exposure
Trezor attributed the scope of the breach to a 90-day target="__blank" rel="noopener noreferrer ">privacy policy says names, addresses, phone numbers and emails used for delivery are deleted from Trezor and fulfillment-partner systems after 90 days, subject to exceptions for unresolved order issues.
The company said this was the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses. Trezor aims to make an “Anonymous Delivery” option available in the European Union by September 2026 and in the U.S. by the end of 2026. The proposed feature includes locker pickup and automatic deletion of shipping identifiers after delivery.
Order-data exposure has repeatedly affected customers of hardware-wallet companies without necessarily compromising the wallets themselves. Ledger said a January 2026 incident at commerce provider Global-e exposed names, postal addresses, email addresses, phone numbers and order details, while leaving Ledger devices and systems unaffected.
Ledger also disclosed in 2020 that an unauthorized party accessed its ecommerce and marketing database, exposing email addresses and, for a subset of customers, names, postal addresses, phone numbers and order information.
Trezor said ShipMonk has secured and hardened the affected systems while the companies work to establish exactly what happened and which data was accessed.