Trezor discloses data breach affecting 13,689 customers

1 hour ago 19

Trezor, one of the most recognized names in crypto hardware wallets, has reported a data breach that compromised personal information belonging to 13,689 customers. The incident puts the company back in the security spotlight after a string of data exposures and persistent phishing campaigns targeting its user base.

This isn’t Trezor’s first time dealing with a customer data incident. In January 2024, an unauthorized party gained access to a third-party support portal used by the company, exposing the contact details of approximately 66,000 users. That breach became a launchpad for phishing campaigns that have continued well into 2025 and 2026.

Attackers obtain names, email addresses, or other identifying information from a data leak, then craft convincing emails or messages impersonating Trezor, urging users to “verify” their wallets or “update” their security settings. The end goal is always the same: get the victim to reveal their recovery seed phrase, which is the master key to their entire crypto holdings.

Trezor has repeatedly warned customers that it will never ask for recovery seed phrases under any circumstances.

Notably, no official confirmation or detail about the breach affecting 13,689 users has surfaced in major news outlets or Trezor’s own communications as of August 13, 2026.

Trezor competes in an increasingly crowded market with rivals like Ledger, which faced its own high-profile data breach in 2020 that exposed information belonging to hundreds of thousands of customers. That incident similarly triggered waves of phishing attacks and even physical threats against exposed users.

For customers affected by the latest breach, the practical advice hasn’t changed much. Be vigilant about unsolicited communications claiming to come from Trezor. Bookmark the official Trezor website and only access it directly. Never, under any circumstances, enter your recovery seed phrase anywhere other than on the physical device itself during a legitimate recovery process.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article