cyberx_█
← back to indexDigital Investigation5 min read

The Trezor breach isn't a phishing problem

The hardware wallet maker has confirmed the exposure of names, phone numbers and home addresses belonging to 13,689 customers, Brazilians among them. The official guidance talks about phishing. The data that leaked is useful for something else — and Brazil ranks among the four countries with the most physical attacks on crypto holders since 2023.

Robert F.
The Trezor breach isn't a phishing problem
▸In this article

On 13 August, Trezor published a notice about an incident at one of its logistics providers. The statement is clear about what was exposed and what wasn't.

What wasn't: anything touching the devices.

"Trezor systems, hardware wallets, private keys, and wallet backups were not affected"

— Trezor, official notice, 13 August 2026

What was, by the company's own account: full name, shipping address, phone number and email for roughly 13,689 customers — 11,742 with full exposure and 1,947 with partial exposure. It covers orders placed between 10 May and 8 August 2026, across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

The guidance to customers is about phishing: never enter your recovery seed on any website, treat urgent messages with suspicion, verify official channels.

It's sound advice. And it falls short of describing the actual risk.

What this particular combination of fields means

Customer database leaks are routine, and the damage is almost always indirect: the data feeds phishing, social engineering, identity fraud.

This one is different for a specific reason. The list doesn't merely say who bought something from a store — it says who holds their own crypto in self-custody, with a high degree of certainty, and it says where that person lives.

This isn't an inference about net worth. It's a confirmation, tied to a physical address, that someone there keeps crypto outside an exchange — meaning there is no intermediary to block, reverse or freeze anything.

Why it matters now

Chainalysis published research this year on what the industry calls a wrench attack — the physical attack against crypto holders:

"A wrench attack is a physical attack in which someone uses violence, or the threat of violence, to force a cryptocurrency holder to hand over their assets"

— Chainalysis, research on physical attacks, 2026

There were 46 documented incidents through June 2026, against 40 at the same point in 2025, with roughly US$30 million taken over the period. Home invasion accounts for 37% of 2026 cases — it was 26% in 2023. Kidnapping accounts for 52%.

And there is one line in the research that ties the two stories together:

"The vast majority of victims are local residents, not tourists, suggesting attackers conduct reconnaissance to identify high-net-worth individuals"

In other words: whoever carries out this kind of attack doesn't pick targets at random. They run reconnaissance — looking for signals that a given person holds crypto, then working out where that person is.

A database with the names, phone numbers and addresses of confirmed hardware wallet buyers is exactly the output of that reconnaissance, delivered ready-made.

France, the United States, Brazil and Thailand account for the highest cumulative counts since 2023. Brazil is no bit player in that statistic, and it is one of the seven countries on the leaked list.

The counterweight, which is also data

It would be easy to stop at the alarm. The numbers don't support it.

The share of attempts that ended in a payout has been falling sharply:

yearattempts resulting in payment
202467% — 32 of 48
202549% — 47 of 95
202626% — 12 of 46

Three out of every four attempts in 2026 did not end in a transfer. That suggests the practice of keeping little value readily accessible, distributing custody and using protections that require more than one step is working — even if none of it erases the human cost of the attack.

The honest reading: the number of incidents is creeping up, and their effectiveness is collapsing.

What changes for the people on the list

Anyone who received Trezor's notice doesn't need to replace their device — the company itself states that the hardware and the keys were untouched, and there is no public reason to doubt it.

What changed is something else: a piece of data that cannot be revoked. You can change a password, you can change an email. A home address, no.

That shifts the response from the digital domain into the physical and behavioural ones. It's worth reviewing how much public exposure links your name to cryptocurrency, how much value sits accessible in a single place, and who knows what about it. Any message that arrives citing your purchase, your order or your address now deserves more suspicion, not less — precisely because it sounds informed.

The lesson that goes unnoticed

Nothing was compromised at Trezor. The incident happened at a logistics provider that exists for a mundane purpose: delivering boxes.

Third-party risk assessments typically classify a shipping company as a low-criticality supplier — it doesn't touch systems, doesn't hold credentials, doesn't process payments. It holds addresses.

For most businesses, that data really is low-criticality. For a business whose customer is, by definition, someone who keeps value at home, the delivery database is among the most sensitive assets there is — and it sat in the one link nobody would have classified as sensitive.

Third-party risk maps are rarely drawn starting from who the end customer is. This case shows why they should be.


Sources

Recent customer data exposed in shipping provider incident, Trezor, 13 August 2026.

Violent Wrench Attacks Targeting Crypto Holders, Chainalysis, 2026.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →