Trezor has warned that some customer phone numbers and shipping addresses were exposed in a breach involving a third-party shipping partner. The hardware wallet maker said its own systems were not compromised and that no device, private key or wallet backup was affected.

The company said only customers who received a notification email were impacted. It added that the scope was limited because shipping partners are required to delete or anonymize order data 90 days after delivery, meaning older order records were no longer being held.

What Trezor says was exposed

According to Trezor, the incident was confined to data held by an external shipping partner rather than its internal infrastructure. The company said the exposed information included some customers’ phone numbers and shipping addresses.

Trezor said customers who did not receive a notice email are not affected. It also stated that, over its 13-year history, it has not previously experienced a breach that exposed customer shipping addresses and phone numbers.

What was not compromised

The company drew a clear line between shipping data and wallet security. Trezor said no device, private key or wallet backup was touched, and that its own systems were not breached.

That distinction is central to the company’s message after the disclosure, as the incident did not involve direct access to customer funds or wallet recovery data based on the information provided by Trezor.

Main risk is phishing and targeted contact

Trezor said the immediate concern is phishing, warning customers to be suspicious of unexpected messages or calls. It specifically advised users never to enter a wallet backup online.

The company also referenced broader physical security concerns often discussed in the crypto sector, sometimes called “wrench attacks,” where attackers use personal information to target wallet holders offline. The article notes that a 2020 breach affecting rival Ledger showed how leaked customer data can create risks beyond fraudulent email.

Response and next steps

In response, Trezor said it is accelerating the rollout of an Anonymous Delivery option. The planned service would use locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers.

The company is targeting availability in the European Union by September and in the United States by the end of the year. For now, Trezor’s confirmed guidance is that only customers who received notification emails were affected, while others are not included in the incident.

Source: decrypt.co