Crypto: 67,000 Trezor customer addresses leaked. Not by Trezor.

Crypto: 67,000 Trezor customer addresses leaked. Not by Trezor.

This one is a good one, and it doesn't tell the story you think it does at all.

Yesterday, Trezor confirmed that the data leak announced in mid-August is much larger than we thought. 67,000 more American customers, with their name, email address, phone number, delivery address and order number. Orders placed between November 2019 and August 2021.

Trezor, for those who don't know, is one of the major manufacturers of those little plastic keys that keep cryptocurrencies offline. Its servers were not affected. Its devices have no problem. Not a single bitcoin moved.

And yet, if you ordered a Trezor in 2020, there's a good chance someone now knows where you live, and also knows why your address is more interesting than your neighbor's.

A crumpled delivery slip on the wet sidewalk in front of a shop window where an intact safe can be seen

The safe hasn't moved a millimeter. It's the package label that's lying in the street.

The good news first, because it's solid

These devices work on a simple idea: the secret that controls your money must never touch a computer connected to the Internet. It's made inside the little box, it stays inside the little box, and you copy it down once on a piece of paper that you put away somewhere. The manufacturer doesn't know it. The carrier doesn't either. Nobody, except you.

So nothing, absolutely nothing that leaked allows anyone to touch a single cent. This isn't a cautious PR formula, it's mechanical: the secret wasn't in the stolen files, because it's nowhere except with you.

And honestly, this is proof that these things are useful. The manufacturer gets its customer files emptied out and its customers don't lose a euro. Try doing the same with an online account. It isn't always this clean, either: a month ago, I explained here how more than 1,800 bitcoins left devices of the same kind without anyone opening a single one, because of a badly configured compilation option at a competitor's company. There, nothing like that. The device did exactly what it was supposed to do.

Except a password, you can change it

A postal address, no.

That's the whole difference between this leak and the ones we're used to. Usually, someone steals a login detail from you, you replace it, you grumble for twenty minutes and it's sorted. Here, someone stole pieces of your real life: your name, your front door, your phone. You don't move house because a warehouse got hacked.

And above all, this information comes with a label stuck on it. It doesn't just say “this person lives here”. It says “this person took an interest in cryptocurrencies five years ago and paid to put them somewhere safe”.

On the left, gloved hands tearing up a password written on paper, on the right, a front door with its mailbox and an open padlock on the doormat

On the left, what you can replace in two minutes. On the right, what you will never replace.

The immediate risk, and by far the most likely one, is a tailor-made scam. A message that knows your real order number, your real model, your real address, and asks you to “check your wallet” on a site that looks uncannily like the real one. When a scammer knows three real details about you, they no longer need to be any good.

The second scenario, rarer but the one that really scares you, is the package. A replacement device that you didn't order, which arrives in pretty packaging, and which has been tampered with. If that happens to you, don't plug it in, don't even open it.

After that, let's keep a cool head: we're talking about people who bought a device five or six years ago, and a good number of them probably don't even have it anymore. That's no reason to shrug your shoulders, it's no reason to panic either.

How you end up leaking when you haven't been hacked

Here's the part I find really interesting, and it has nothing to do with cryptocurrencies.

You order from a seller. That seller doesn't handle the packages themselves, they hand your file over to a warehouse that packs and ships on their behalf. That warehouse, to know how many packages it sends out per day and per region, connects a dashboarding tool to its customer file, a thing that turns rows into pretty charts for Monday's meeting. That's three companies. You only know one.

A store, a warehouse and an office building connected by an arrow, with leaves escaping from an open third-floor window

Three companies share your address. You chose one of them.

It's the third one that left the window open. The graphics software publisher warned the warehouse on August 6 that a flaw in its tool had been used to reach customer data. The warehouse noticed the intrusion on the 10th. Trezor warned its customers on the 13th.

Three days between noticing it and the public announcement, with the subcontractor's name written in black and white, that's worth pointing out. Half the companies on the planet would have written “a logistics partner” and closed the file.

And then there's the detail that really hurts

These orders from 2019 to 2021 should never have been there.

Trezor says it received written assurances several times that this old data had indeed been deleted, as required by the contract and its own retention policy. It was still there. Five years later, sitting nice and warm in a database that nobody was looking at anymore.

And this isn't a paperwork detail, it's the whole story. Without those 67,000 ghost records, the leak would have stopped with the roughly 13,000 people who had ordered that summer. The file that caused the most damage was the one that wasn't supposed to exist.

An official certificate placed on sealed, dusty archive boxes, with an unplugged shredder in the background

The destruction certificate, on top. The boxes, underneath. Nobody ever lifted the lid.

This should interest you even if you've never touched a cryptocurrency in your life. A box checked in a contract, a certificate received by email, a retention policy displayed on a website, none of that erases a damn thing. What erases it is someone initiating the deletion and someone else checking that it happened. Yesterday I was talking about Anthropic, which spent a summer wondering where to store a month's worth of its customers' conversations. The real question, in both stories, is the same: who holds what, where, and for how long without anyone knowing.

What do you do, concretely

Nothing to change on your device, it's doing just fine. Four habits, though.

No manufacturer, ever, will ask you for the twelve or twenty-four words in your recovery phrase. Not by email, not over the phone, not on a website, not during an update, not “to check that everything is all right”. A message asking you for them is a scam, period, there is no exception to look for.

Be especially wary of a message that knows your order number or the exact model you bought. That's precisely what the leak has handed to the scammers, and that's what makes us believe it.

A package you didn't order that contains equipment gets sent back or ends up in the trash. You don't plug it in.

And the general habit, the one I'm applying to myself from now on: when you buy an object that says something about you, check whether there's a pickup point. Your address won't end up in the files of three companies whose names you don't know.

What I take away from this story

The device did its job perfectly, and it was useless.

You can put your gold in the best safe in the world, if the list of people who bought that safe is lying on the sidewalk with their addresses on it, you haven't solved your problem, you've moved it. And that's the kind of thing you have no control over: neither you nor Trezor chose for the old 2019 file to still be sleeping somewhere in 2026.

So how many lists like that are left, with subcontractors' subcontractors, along with a lovely destruction certificate neatly filed away in a folder nobody will ever open again ? Honestly, I'd rather not know!


Sources

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙