Crypto加密

Trezor data breach exposes personal details of nearly 14,000 hardware wallet holders

Cold storage hardware wallets are built on the premise that offline private keys cannot be reached by hackers. Against the backdrop of that assumption, hackers stole personal details from nearly 14,000 holders of Trezor devices,…

By Dev Okafor·August 13, 2026·二〇二六年八月十三日·2 min read

Key takeaways

  • Hackers stole personal details from nearly 14,000 holders of Trezor hardware wallets in a breach of the company's customer data systems, not the private keys on the devices.
  • This is the second attack targeting cold storage wallet users within a two-week period.
  • The stolen data exposes individuals as identifiable cryptocurrency holders, enabling targeted phishing and social engineering attacks.
  • The devices' offline private keys were not compromised, since the breach hit internet-connected company systems rather than the hardware itself.
  • Two attacks on cold storage holders in a fortnight suggest the segment is drawing focused attention from attackers, though it is unknown whether the two events are linked.

Cold storage hardware wallets are built on the premise that offline private keys cannot be reached by hackers. Against the backdrop of that assumption, hackers stole personal details from nearly 14,000 holders of Trezor devices, the second attack to target cold storage users in two weeks. The breach hit customer data held in company systems, not the private keys stored on the devices themselves.

The gap between device security and company data

A hardware wallet's security model covers what lives on the device. Private keys stay offline, away from internet-connected systems. That architecture, when it works, prevents direct theft of digital assets. What the model does not address is the data a company accumulates about the people who buy its products. That information sits in company systems connected to the internet, and it can be breached independently of anything happening on the device.

When it is, the people exposed are identifiable as cryptocurrency holders. Personal details in the hands of an attacker provide the basis for targeted phishing or social engineering attempts, attacks shaped around the knowledge that a specific person holds digital assets. That is the mechanism at play here, separate from any question about what is on the Trezor hardware itself.

Two weeks, two attacks: a sector signal

The interval is what sharpens this story. Single data breaches happen across every industry and rarely define a pattern. Two incidents hitting cold storage holders in a fortnight suggest this segment is drawing focused attention from attackers. Whether the two events are linked has not been established.

The read-through for cold storage providers across the sector is direct. As cryptocurrency participation has grown, the customer databases behind hardware wallet companies have grown alongside it. Those databases now appear to be the target. The devices hold the keys offline. The customer data never was.

Source · 來源

ft.com

Share · 分享

Frequently asked

Were the private keys or cryptocurrency on the Trezor devices stolen?

No, the private keys stored offline on the devices were not compromised; the breach affected customer data held in Trezor's internet-connected company systems.

How many people were affected by the Trezor breach?

Personal details of nearly 14,000 Trezor hardware wallet holders were exposed.

Why is the stolen customer data dangerous?

It identifies specific individuals as cryptocurrency holders, giving attackers the basis for targeted phishing or social engineering attempts shaped around the knowledge that a person holds digital assets.

Is this an isolated incident?

No, it is the second attack to target cold storage users in two weeks, though it has not been established whether the two events are linked.

Why did a hardware wallet's security model not prevent this breach?

The security model only covers the private keys on the device, not the customer data a company accumulates, which sits in internet-connected systems and can be breached independently.