An additional 67,000 U.S. customers of Trezor have been affected by a data breach tied to orders placed between November 2019 and August 2021. The breach exposed customer order information—names, email addresses, and shipping details—creating a roadmap for targeted phishing campaigns.

While Trezor devices themselves remain uncompromised, the exposed purchase history gives attackers ammunition to craft convincing social engineering schemes. Malicious actors can impersonate Trezor support, reference specific order details, and trick users into revealing seed phrases or private keys. On-chain analysis shows compromised seed phrases typically result in rapid fund outflows, often within hours of exposure.

The incident highlights a critical gap in self-custody security: hardware wallets protect keys from network attacks, but customer data breaches expose the human element. Users who ordered during the affected window should immediately verify the authenticity of any Trezor communications by visiting official websites directly, avoid clicking links in unsolicited messages, and enable multi-factor authentication on all associated accounts. Never share recovery phrases with anyone under any circumstance.

Trezor is expected to issue detailed security advisories as its investigation continues. The breach will likely force a reckoning across the hardware wallet industry regarding customer data storage and handling protocols.