Whether you are affected by the Trezor data breach comes down to a single question: is there an email from help@trezor.io about the incident in your inbox? Trezor says it notifies every affected person individually. Anyone who has not received that message is, according to the manufacturer, not in the exposed records.
On September 4, 2026, Trezor widened the incident for the second time. Around 67,000 further customers in the United States were added to the 13,689 reported in August, bringing the total to just over 80,000 people. Exposed were the full name, delivery address, phone number, email address and order number. Not exposed were the contents of the parcels, the devices themselves, private keys or wallet backups.
This article answers the question behind the headline that nobody has answered in German so far: whether German customers appear in this second wave at all, how you check that, and what an open address book means for someone who holds crypto assets in self-custody.
Am I affected by the Trezor data breach? The check takes two minutes
Trezor has taken the same route for both waves: those affected are informed directly by email, sent from help@trezor.io


English (US)