Trezor's Breach Costs More: Hardware Wallets Weren't Enough
The breach is not Trezor's systems — the private keys stay offline, the cold storage holds.
Trezor's Breach Costs More: Hardware Wallets Weren't Enough
Hardware crypto wallet maker Trezor has confirmed a second data breach of a third-party email provider, exposing hundreds of thousands of customer email addresses to scammers who are now running targeted phishing campaigns against affected users, according to TechCrunch.
The breach is not Trezor's systems — the private keys stay offline, the cold storage holds. But the attack surface was never the wallet. It was the human behind it. Scammers now hold verified lists of people who own crypto hardware, which is a self-selecting dataset of holders serious enough to spend money on security. That is a high-value target list, handed over by a vendor Trezor trusted and didn't fully control.
This is the second time a Trezor supply chain partner has leaked. The pattern matters more than the incident. A company whose entire brand proposition is security — "your coins, your keys" — cannot absorb repeated third-party failures without the brand itself becoming the liability.
Per CoinDesk, Bitcoin is already navigating a difficult week, with rising yields and inflation data adding pressure across the crypto market. A trust crisis at one of the sector's most recognised hardware brands lands at the worst possible moment.
If you hold crypto and use Trezor, do one thing now: go to your email provider, check what address is associated with your Trezor account, and set up a separate alias for any crypto-related correspondence. It costs nothing and removes you from the next list before it's compiled.