Stay informed with free updates
Simply sign up to the Cyber Security myFT Digest — delivered directly to your inbox.
The personal details of nearly 14,000 crypto holders have been exposed in a data breach affecting what is meant to be the most secure way to hold keys that give access to digital tokens, potentially putting them at risk of criminal attack.
Trezor, which sells hardware crypto wallets, said on Thursday that a data breach at one of its shipping providers had resulted in the names, addresses, phone numbers and email addresses of 11,742 buyers of the secure devices being exposed, while a further 1,947 customers’ names, domicile cities and emails had been hacked.
It comes as crypto holders have increasingly become targets of physical as well as online attacks, as criminals try to seize their assets.
The Prague-based company sells hardware wallets, which are small devices similar to USB sticks on which users store their private keys away from the internet and potential online hacks. Also known as “cold” wallets, these devices are meant to be the least vulnerable way for crypto holders to secure access to their tokens stored online.
They have risen in popularity as investors seek a safe way to secure their assets at a time when hacks at crypto venues have climbed to record numbers.
The security of cold wallets has come under increasing question, with Thursday’s incident being the second time in two weeks that users of cold wallets have faced problems. More than $100mn was stolen from holders of Coldcard hardware wallets on July 30 after a bug led to users’ private keys not being generated securely enough, leaving them prone to hacking.
Digital asset intelligence firm TRM Labs said the Coldcard hack “reinforces that self-custody relocates risk rather than eliminating it”.
Trezor said the data breach affected people in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who received their devices between May 10 and August 8. The company said it was “deeply sorry” and that “affected customers could experience an increase in phishing attempts”.
Digital asset holders have become targets of physical attacks in recent years, as thieves try to steal their crypto. In one high-profile case, the co-founder of rival hardware wallet firm Ledger and his wife were kidnapped in France last year and later freed.
“Criminals have recognised that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form,” said blockchain data provider Chainalysis.
Kidnappings accounted for more than half of the 46 violent attacks on crypto investors recorded so far this year, while more than a third of the attacks involved home invasions, according to Chainalysis. The figures are likely to be an underrepresentation, as some crypto holders may not have reported that they were attacked.
Trezor said it was working on an anonymous delivery option that would allow customers to order hardware wallets “without linking the purchase to your home address or real-world identity”, which it aims to make available by September across the EU.
“We absolutely understand how serious this is and the potential risks it poses to our customers,” Trezor told the FT, adding that the company was “not aware of any confirmed case of a scam, a hack or a threat to a customer’s safety resulting from this exposure so far.”


