On 17 January 2024, at 20:20 CET, Trezor identified unauthorised access to the third-party support ticketing portal it used. SatoshiLabs said up to 66,000 people who had contacted Trezor Support since December 2021 might have had names or nicknames and email addresses exposed. Postal addresses and phones were stored on the same class of system; Trezor said it did not believe those left. Devices, firmware, and keys were not in the ticket tool.
The company also said attackers had already emailed some customers posing as support and asking for recovery seeds — including a story about “firmware validation”. That is the harm model. A helpdesk dump is a phishing kit.
What happened
This is a vendor story, like a shop database or a parcel warehouse. The 2020 Ledger dump and the 2026 ShipMonk incident are cousins, not clones: different company, different files, same lesson. Cold storage does not encrypt the email you used to file a ticket.
Why it matters
If you wrote to Trezor Support in that window, expect better-targeted mail. Nobody at Trezor needs your 12 or 24 words. Nobody needs them in a web form. See how crypto wallets actually work, what cold storage is, and the practical checklist. If you buy a device later, remember the invoice and the ticket are still company records.
What happens next
More phishing, a vendor change, and a 2026 sequel in logistics. We will not tell you to throw the hardware away — or to trust a support email because it spelled your name right. Nothing here is a review score or a prompt to move coins tonight.






