We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026.
The data exposed:
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email.
Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts.
NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
We are investigating this situation and will post updates on our blog:
https://t.co/JGrttMs4Ev
I just received my @Trezor Trezor Safe 3 Bitcoin Only.
The outer shipping label the one every delivery driver, neighbor, and anyone near my mailbox can read says exactly that.
Trezor Safe 3 Bitcoin Only.
Not “electronic device.” Not “consumer electronics.” Not a generic description that any shipper could legally use.
The full product name. On the outside. For everyone to see.
This is not a customs requirement. US domestic shipments have no international customs declarations.
There is no legal obligation that forced this. This was a choice made by Trezor to print the exact contents of your package on the label that faces the world.
Every person in that delivery chain now knows you bought a Bitcoin hardware wallet. The driver. The sorting facility worker. The neighbor who grabbed your package from the porch.
This is not paranoia. This is operational security 101.
Supply chain attacks are real. Physical theft targeting Bitcoin holders is real. Social engineering using purchase data is real. The threat model exists.
Trezor knows it exists they sell products specifically designed to protect against it.
And then they print the product name on the outside of the box.
Satoshi understood something that apparently still needs to be explained to Bitcoin companies in 2026.
Privacy is not optional. Privacy is not a feature. Privacy is a prerequisite for security.
Satoshi never revealed their identity out of a deep understanding that exposure creates attack vectors. That information about who you are and what you hold makes you a target. A company selling tools for financial sovereignty should understand this better than anyone.
We just watched Coldcard burn after a firmware failure that drained hundreds of Bitcoin. That was invisible, buried in code. This is different. This is visible.
This is simple. This is a choice.
Trezor could print “electronic device” tomorrow and fix this entirely. No engineering. No firmware update. One decision by one person in their operations team.
If Satoshi had seen their home address linked to “Bitcoin Only” on a shipping label, they would have returned it. And they would have been right.
The box is sitting in front of me right now. Unopened. I haven’t been able to bring myself to open it not because of what’s inside, but because of what was written on the outside.
This is my first experience with Trezor. And I am genuinely disappointed.
One week ago I was processing the Coldcard disaster. That was a technical catastrophe. This is something else a simple, avoidable mistake that puts customers at risk before they ever touch the product.
Being a Bitcoiner in 2026 means caring about details that feel small but aren’t. It means holding the companies in this space to a higher standard because the stakes are higher.
It shouldn’t be this hard. And they should know better.