Trezor's New Data Breach Hits 67K More Users—Are You One?
Jennifer Davis ·
Listen to this article~3 min

Trezor's shipping provider breach now affects 67,000 more US users. Here's what leaked and how to protect yourself from phishing and social engineering scams.
If you bought a Trezor hardware wallet and had it shipped to a US address, you might want to sit down for this. The company just confirmed that another 67,000 customers in the United States had their personal data exposed. That's on top of the 66,000 users affected in an earlier breach. So yeah, this isn't a small oops—it's a pattern.
### What Exactly Happened?
Trezor doesn't ship products directly. They rely on a third-party logistics provider to handle orders and deliveries. That provider got hacked. Names, email addresses, phone numbers, and physical addresses were all part of the leaked data. No seed phrases, no private keys, no funds—but your identity? That's a different story.
### Why This Matters More Than You Think
You might be thinking, "So what? My email is already out there." But here's the thing: this kind of data is gold for scammers. They can call you, pretending to be Trezor support, and say something like, "We detected suspicious activity on your wallet. Please verify your seed phrase." If you fall for it, your crypto is gone. And there's no customer service hotline to get it back.
These attacks are called social engineering, and they work because they feel real. The scammer knows your name, your address, maybe even the last four digits of your phone number. That builds trust fast.
### How to Protect Yourself Right Now
- **Never share your seed phrase.** Not with Trezor, not with anyone. Trezor will never ask for it.
- **Hang up on unsolicited calls.** If someone claims to be from Trezor support, end the call and contact Trezor directly through their official website.
- **Use a separate email for crypto.** If you used your main email for Trezor, consider switching to a dedicated one for exchanges and wallets.
- **Enable two-factor authentication (2FA).** Use an app like Google Authenticator or Authy—not SMS, which can be SIM-swapped.
- **Watch for phishing emails.** Check the sender's address carefully. Scammers love to spoof official domains.
### The Bigger Picture for US Crypto Users
This breach is a wake-up call. If you're new to crypto, you might think hardware wallets are invincible. They're not. They protect your keys, but they can't protect your personal data once it's out there. The best defense is awareness and a healthy dose of skepticism.
As one security expert put it: "In crypto, you are your own bank. That means you're also your own security team."
So take a few minutes today to review your accounts. Change passwords if you reused them. And if you get a weird email or call about your Trezor, don't engage. Just delete, block, and move on.
Your crypto is only as safe as your habits. Stay sharp out there.