Trezor 这次没丢私钥,但泄露的东西可能更吓人!
Trezor 刚发布的公告很多人私信我:
先帮大家明确下,这个属于:隐私/身份数据泄露事件,不是私钥/硬件钱包安全事件。
Trezor 表示出问题的是第三方物流商 ShipMonk,Trezor 自己的系统、设备和服务没有被攻破。
已确认约 11,742 人泄露姓名、邮箱、电话和收货地址,另有 1,947 人只泄露姓名、城市和邮箱;
但是这他娘的也很恐怖,
相当于别人拿到了:你是谁 + 你住哪里 + 你是一个 Trezor 用户,这个连串信息,这会让你成为质量非常高的诈骗目标。
所以目前 Trezor 能做的,就是警告大家:任何主动要求你提供 wallet backup、PIN、密码或验证码的人都应该直接视为诈骗;Trezor 不会主动要求用户验证钱包备份。
再加上最近圈内名人被绑架的事件,这种泄漏我觉得也非常吓人,如果是我被泄漏,我恨不得搬家。
我至少得到了几点:
1️⃣所以硬件钱包虽然让大家安全性提高了一些,但是需要收货地址,所以以后如果购买硬件钱包,是不是搞个中转接受点好点?
2️⃣安全从来不只有私钥安全这一件事。硬件钱包解决的是“别人怎么拿不到我的私钥”;这次 Trezor 事件提醒我们的,是“别人最好连我是一个硬件钱包用户都不知道”。
3️⃣专门邮箱 + 尽可能独立手机号 + 非家庭收货地址 + 不公开主钱包地址。
就像
@cz_binance 也在 X 提醒大家:
未来真正成熟的 Crypto 安全,不会再是“买哪个硬件钱包”的问题。
而应该变成:私钥隔离 + 钱包分层 + 身份隔离 + 链上隐私 + 现实世界安全
这五件事情组成一个完整系统。
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days prior to August 8th, 2026.
The data exposed:
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
All affected customers have been contacted separately by email.
Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts.
NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.
We are deeply sorry to the community and those affected.
We are investigating this situation and will post updates on our blog:
显示更多