Trezor Data Breach Widens, 67,000 More Users Exposed
Hardware wallet maker Trezor confirms a larger data leak as partner records dating back to 2019 surface, raising fresh questions about third-party data retention.

Adrian Cole
Markets & Mining Editor, RefreshCoin
Hardware wallet manufacturer Trezor disclosed that roughly 67,000 additional customers were affected by an ongoing data breach, widening the scope of an incident that first surfaced earlier in 2026. The newly identified records show that some user information held by a third-party partner was retained far longer than the 90-day window Trezor says it had contractually required, with entries stretching back to 2019. The disclosure lands at a sensitive moment for self-custody users, who rely on hardware wallet brands to keep personal data, support tickets and shipping details out of the hands of phishers and social engineers.
What did Trezor actually disclose?
In the latest update, Trezor confirmed that the total number of affected users is now significantly larger than the first batch reported earlier in the year. The company attributes the expansion to a third-party support partner that did not purge customer records within the agreed 90-day window. Some of the exposed records include names, email addresses and partial contact details tied to support interactions that date as far back as 2019. Trezor stressed that the breach is limited to customer data held by that partner, and that the company has not identified direct compromise of its own internal systems beyond what was already known.
The 2019 timestamp matters because it shows how far the partner drifted from the agreed retention policy. A 90-day limit would have aged out those records years ago, suggesting either an operational failure at the partner or a slow audit process at Trezor that allowed old records to persist. The records are not seed phrases or device PINs, so on-chain wallet funds remain technically safe, but they are exactly the kind of personal information that gets weaponized in targeted phishing attempts. Trezor says it has started notifying the additional 67,000 users and is reviewing its vendor agreements to shorten retention and tighten deletion audits.
Why does this matter for hardware wallet users?
Hardware wallets are sold on the promise that the user keeps full control of private keys, but that promise is only as strong as the company's security hygiene. Customer databases, support tickets and shipping logs are outside the cryptographic core of the device, yet they are the entry point for most real-world attacks. Phishing emails that reference an old order number, a real shipping address or a prior support ticket are dramatically more convincing than generic spam, and that is the risk profile Trezor users now face on a larger scale.
The incident also highlights a structural problem in the hardware wallet industry: most brands outsource at least part of their support, logistics or marketing operations to outside vendors. Each of those vendors becomes a holder of sensitive customer data, multiplying the attack surface beyond what a single company's logo might suggest. For traders and long-term holders, the practical takeaway is that buying a hardware wallet does not eliminate identity risk, only key custody risk. Anyone who has ever contacted Trezor support, opened a ticket or shared an email for shipping updates should treat the next round of unsolicited messages with extra suspicion.
What is the background of the Trezor breach?
The story began earlier in 2026 when Trezor reported that an unauthorized party had accessed data tied to a subset of its customers. That initial disclosure drew attention because Trezor is one of the best-known hardware wallet makers, competing directly with Ledger in a market that has grown alongside self-custody adoption. Trezor said at the time that the breach stemmed from a third-party vendor involved in support and outreach, not from a compromise of Trezor's own production environment. The first round of exposed data was already sizable enough to trigger phishing warnings across crypto Twitter and forum threads.
The new disclosure effectively doubles down on that initial finding. Instead of revealing a new attack vector, it shows that the original vendor failed to follow the data minimization rules Trezor says it had built into the contract. Records from 2019 sitting in a vendor database in 2026 is a textbook retention gap, and it has now turned a contained incident into a broader one. Regulators in Europe have already pushed the wider crypto industry toward shorter retention periods and explicit consent under GDPR, so a vendor holding seven-year-old support records is also a compliance question, not just a security one. Trezor has not publicly named the partner involved, but the description matches the kind of marketing and CRM vendors that hardware wallet companies commonly use to handle newsletters, ticket routing and user outreach.
How does this fit the wider pattern of crypto data leaks?
The Trezor case is part of a long list of crypto-related data exposures over the past several years. Centralized exchanges, hardware wallet vendors and DeFi front-ends have all been hit, and the recurring lesson is that user databases are a soft target compared with on-chain infrastructure. Attackers know that a verified email plus a shipping address is enough to run convincing impersonation campaigns that can lead to seed phrase theft, sim swaps or account takeovers on linked services. The economics favor the attacker: stealing a list of 67,000 crypto-curious email addresses is cheap, and even a tiny conversion rate on phishing pages can be lucrative.
Self-custody education has improved since early hardware wallet incidents, but the threat model has also evolved. Earlier leaks tended to focus on email lists scraped from public sources. Modern leaks increasingly come from third-party SaaS vendors, marketing platforms and customer support tools, which is exactly the pattern visible here. The combination of longer retention than promised and delayed discovery is what turns a single breach into a multi-year exposure window. For the broader industry, the Trezor update reinforces a trend that regulators have started to act on: data minimization, vendor audits and shorter retention windows are becoming baseline expectations rather than nice-to-haves.
What should affected users watch for next?
The immediate risk vector for affected customers is targeted phishing. Users who receive emails referencing past Trezor support tickets, order numbers or shipping addresses should treat any embedded links or attachments as suspect, even if the messages appear to come from a familiar address. Trezor has reiterated that it will never ask for recovery seeds, device PINs or firmware passwords, and any message that does should be treated as malicious regardless of how plausible it looks. Affected users are also advised to rotate email addresses where feasible and to enable hardware-based two-factor authentication on any exchange accounts linked to the exposed email.
On the corporate side, watch for further updates on the identity of the third-party vendor, the total final count of exposed records and any regulatory action. European data protection authorities have shown willingness to fine companies that hold personal data beyond stated retention limits, and a partner retaining 2019 data into 2026 could attract scrutiny under GDPR's storage limitation principle. If Trezor decides to migrate support operations to a new vendor or to bring them in-house, that transition itself can introduce new risks during the cutover. Traders should also keep an eye on sentiment around hardware wallet stocks and competing brands, because competitors tend to use high-profile incidents to market their own security setups, which can shift short-term narrative cycles in crypto media.
Could this affect Trezor's market position?
Trezor and Ledger have long been treated as the two flagship consumer hardware wallet brands, with smaller players like Bitbox, KeepKey and various open-source alternatives serving niche audiences. Repeated security incidents do not usually erase brand trust overnight, because switching hardware wallets has real friction: new device purchases, seed migrations and the loss of any device-specific workflows. However, each incident chips away at the perception that buying from an established brand is a complete security solution, and that perception is what the industry sells alongside the device itself.
The longer-term question is whether Trezor will face the kind of class-action or regulatory pressure that has hit other crypto firms after large breaches. If European regulators open a formal inquiry into the partner's retention practices, the resulting timeline could drag public attention back to the story several times over the coming year. For now, the most concrete numbers to track are the final count of affected users, the official confirmation of which partner was involved and any published retention audit that Trezor commits to going forward. Until those details land, the breach remains an open data story rather than a closed one.
Mentioned in this article
Frequently asked questions
How many Trezor customers were affected in total?
Trezor disclosed an additional 67,000 customers in the latest update, on top of the users already named in the earlier disclosure. The company has not yet published a single combined total, so the final figure may still grow if more old records are uncovered in the partner's systems.
Were any crypto funds or seed phrases stolen?
Trezor says the breach involves customer data held by a third-party support partner, not seed phrases, device PINs or firmware passwords. On-chain wallet funds were not reported as directly compromised, though the exposed personal data can be used for phishing attacks aimed at stealing those secrets later.
Why were 2019 records still on file?
Trezor says its contracts with the partner required data to be deleted after 90 days. The 2019 timestamp suggests the partner failed to honor that retention policy, turning a short-lived data window into a multi-year one. Regulators in Europe treat holding personal data beyond the stated retention period as a potential GDPR violation.
Comments(0)
No comments yet. Be the first to weigh in.