Trezor Data Breach Exposes Thousands of Crypto Owners to Phishing Scams

TL;DR
- Trezor confirmed a breach at its third-party email marketing provider exposed names and email addresses of nearly 100,000 users, but no seed phrases, PINs, or funds were compromised.
- Scammers are already using the stolen contact list for highly targeted phishing emails pushing fake firmware updates and support alerts to steal recovery seeds.
- This is the second major incident involving a Trezor vendor after previous MailerLite and support-ticket breaches, raising fresh concerns about supply-chain security for crypto firms.
What Happened
Trezor, the Czech maker of one of the world's most popular hardware wallets, has confirmed that an attacker breached its third-party email provider and stole the contact details of nearly 100,000 of its users.
The company said it was notified of unauthorized access to a mailing database used for newsletters and educational campaigns. Exposed data includes names and email addresses of customers who had opted in for communications. Trezor stressed that no passwords, PINs, balances, wallet backups, or 24-word recovery seeds were stored on the affected system and therefore were not exposed.
In a statement shared on its official blog and social channels this week, Trezor said it immediately revoked access for the compromised provider, launched an internal investigation, and notified data protection authorities. Affected users are now being contacted directly from Trezor's verified domain.
How Scammers Are Targeting Victims
As with past crypto data leaks, the real danger is not the leaked emails themselves, but what comes next: sophisticated phishing.
Security researchers and victims report a surge in convincing scam emails impersonating Trezor support since the breach. The messages warn of a critical security patch, wallet deactivation, or failed backup verification and urge users to click a link or download a new version of Trezor Suite.
Those links lead to near-perfect clones of trezor.io that prompt users to enter their 12, 20, or 24-word recovery seed to "migrate" or "validate" their wallet. Once entered, attackers can instantly drain funds from the real hardware wallet remotely. Other variants include fake customer support calls, SMS messages, and even physical letters referencing the victim's real name to build trust.
Trezor reiterated it will never ask for your recovery seed, PIN, or passphrase via email, chat, or phone. Any message that does is a scam.
Why This Is the Second Strike for Trezor Partners
This incident painfully echoes previous supply-chain breaches that have haunted Trezor and its rival Ledger.
In early 2023, attackers compromised Trezor's email marketing platform MailerLite via a phishing attack on an employee, sending malicious firmware-update emails to over 130,000 contacts. In January 2024, Trezor disclosed another incident where unauthorized access to a third-party support ticketing portal exposed contact details of up to 66,000 users.
While Trezor's hardware devices themselves have never been hacked remotely, critics argue the repeated vendor breaches create a persistent phishing risk pool. With names, emails, and purchase history circulating on cybercrime forums, victims can remain targets for years. The pattern also highlights a broader industry problem: crypto companies often outsource email, support, and shipping, creating attractive weak links for hackers who can't break the cryptography itself.
What Crypto Holders Must Do Now
If you own a Trezor - or any hardware wallet - assume your email is compromised and act accordingly.
First, stay skeptical of all inbound communication. Do not click links or download attachments from emails claiming to be from Trezor. Always navigate directly to trezor.io and verify announcements on Trezor's official X account and blog. Check sender addresses carefully for subtle misspellings like trezor-support.net or trezor-update.com.
Second, never share your recovery seed. No legitimate firmware update requires you to re-enter your seed on a computer or website. Keep your seed offline on paper or metal, never photograph it or store it in email or cloud notes, and consider adding a passphrase for plausible deniability.
Third, isolate your crypto identity. Create a new, unique email address for crypto accounts with strong two-factor authentication, and consider using email aliases going forward. Trezor users who received a breach notification should be extra vigilant for at least the next 12-24 months.
The Bigger Picture for Wallet Security
The Trezor breach is a reminder that in crypto, you don't need to lose your private keys to lose your funds - you just need to be tricked into giving them away.
Hardware wallets remain one of the safest ways to store Bitcoin, Ethereum, and other assets because they keep keys offline. But as this leak shows, attackers have shifted from breaking devices to breaking trust, exploiting outsourced marketing and support systems to launch mass social-engineering campaigns at minimal cost.
For the industry, the incident will likely renew pressure to minimize data collection, encrypt customer databases, and audit vendors more aggressively. For users, the lesson is blunt: your inbox is now part of your attack surface. Treat every crypto-related email as hostile until proven otherwise.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!