Trezor Email Provider Breached in Chip-Flaw Phishing Attack
Trezor is a prominent maker of Bitcoin hardware wallets, devices designed to keep private keys offline and reduce exposure to internet-based attacks. The incident does not establish that Trezor wallets or their chips were compromised. Instead, attackers exploited a third-party communications channel, underscoring how trusted-looking messages and supply-chain weaknesses can threaten users even when the underlying hardware remains secure.
Trezor said hackers breached its third-party email provider and sent phishing messages disguised as an urgent security warning. The emails falsely claimed a chip flaw had weakened the randomness used to generate wallet recovery seed phrases and directed recipients to a malicious link. Trezor took down the attack domain, opened an investigation and urged users not to click suspicious links. It has not disclosed the number of recipients, a precise incident date or any financial losses.
All Coverage
2 original reportsThe Backstory
The history behind this eventTrezor Data Breach Widens to Expose 67,000 More Customers
Hardware wallets are designed to keep cryptocurrency private keys offline, but customer order records can still give attackers valuable material for targeted phishing. Trezor’s exposure stemmed from a security breach at logistics provider ShipMonk rather than a compromise of the wallets themselves. Private keys and user funds were not affected, though names and delivery details can make fraudulent messages appear more convincing.
Trezor said the widening breach exposed another 67,000 US customers whose orders were placed from 2019 through 2021, bringing the reported total affected population to about 80,000. The records included names, phone numbers and addresses. Trezor said ShipMonk had repeatedly assured it that the data had been deleted and expressed disappointment that the vendor failed to follow the required deletion procedures, while warning customers to remain alert for phishing emails.
Trezor Shipping Partner Breach Exposes Data of Nearly 14,000 Customers
Trezor, a maker of hardware wallets designed to keep cryptocurrency private keys offline, still relies on outside providers to process orders and deliveries. That creates a separate supply-chain risk: leaked customer details can help criminals identify crypto holders and craft convincing phishing messages, impersonation attempts or even physical threats. The incident underscores that cold-storage security does not eliminate exposure created by commerce and logistics systems.
Trezor said in August that a breach at fulfillment and logistics partner ShipMonk exposed personal information belonging to nearly 14,000 customers, including some shipping addresses. Reports linked the intrusion to a possible Metabase vulnerability, though the compromise occurred in the provider’s environment. Trezor notified affected customers and said its hardware wallets, users’ private keys and cryptocurrency funds were not compromised in the incident.
Trezor Discloses Safe 7 Chip Flaw but Says User Funds Are Secure
Trezor Safe 7 is a hardware wallet designed to store private keys for crypto assets offline, with its TROPIC01 secure chip protecting sensitive data. Ledger's security research team found a vulnerability in the chip. Because hardware wallets rely on physical isolation for protection, the flaw raises questions about asset security if a device is stolen.
As of July 19, 2026, Trezor said an attacker would need physical access to a Safe 7, specialized equipment and advanced technical expertise to exploit the flaw. No attacks have been reported, and known user losses stand at $0. The company stressed that funds remain secure but has not announced a timeline for a fix.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →