xmr.club
EN 中文 ES RU
★ FRONT-PAGEASageSwap— Anonymous swap — no KYC, no AML hold, no IP logging, declines law-enforcement requests.→
/wallets · verified 2026-08-14

Trezor

B

Open-source-firmware hardware wallet with XMR support via Monero GUI + Feather. Grade B. Live incident: 2026-08-13 shipping-provider breach exposed 11,742 customers' full PII (name + phone + shipping address) to the black market — physical-safety risk, not phishing risk. Read the incident block before ordering.

Maintainer: SatoshiLabs (Trezor)

SatoshiLabs (Trezor) also runs: Trezor Suite A

Incident timeline

  1. 2026-08-20auto Trezor published an official 2026-08-13 blog naming ShipMonk as the breached fulfillment partner and restating 11,742 full-address records plus 1,947 partial; devices and firmware remain unaffected. After the first post, Trezor said the 1,947 partial cohort (name/city/email only) may include older-than-90-day orders…

At a glance

Grade
B ()
KYC posture
light kyc
Fees
Hardware device $69+ · Network fees only
Last verified
2026-08-14
Operating since
2014 · 12y — operating_since estimated from about-page heuristic; WHOIS and archive.org both returned no signal
Incident
⚠ Active since 2026-08-13 — /incidents
B Why grade B?

Solid pick. Verified working but with a meaningful caveat (UX rough, smaller market, intermediate trust step, partial coverage). Listed because the trade-off is sometimes worth it.

Full rubric + 7-step verification walkthrough at /methodology.

curator verdict · bottom line

Curator Verdict & OpSec Breakdown

THE BOTTOM LINE

Trezor is a verified, functional Monero wallet that performs solidly for day-to-day use, provided readers account for its specific operational trade-offs.

✓

Proven Strengths

  • ▸ Non-custodial architecture: user retains full custody of private keys throughout execution.
  • ▸ Open-source codebase: public code repositories allow independent verification and audit.
  • ▸ Established operational track record: serving users continuously since 2014 (12 years).
⚠

OpSec Trade-offs & Caveats

  • ▸ ACTIVE INCIDENT (2026-08-13): A third-party shipping provider used by Trezor was breached, exposing full names, phone numbers, email addresses, and shipping addresses of customers who ordered in the 90 days prior to 2026-08-08. Trezor's own count: 11,742 customers with full exposure + 1,947 with partial (name + city + email). Affected countries: US, UK, Sweden, Colombia, Brazil, Italy, Portugal. Trezor's public statement leads with 'our devices remain secure' and frames the risk as phishing. The reader-facing reframe is physical: shipping addresses of confirmed crypto holders in the hands of any buyer of the leaked data is home-invasion / stalking / $5-wrench-attack territory, not inbox phishing. Trezor firmware and devices are unaffected by this incident — the exposure is entirely on the fulfillment supply chain. See the curator guide for the operational response.
  • ▸ Heuristic KYC triggers: transactions or accounts may be frozen for ID review if flagged by automated risk rules.
  • ▸ Clearnet-only footprint: lacks an official .onion hidden service mirror; exposes visitor network IP unless routed through VPN/Tor.

Review

Live incident (2026-08-13). A Trezor shipping-provider breach exposed the full PII (name + phone + email + shipping address) of 11,742 customers who ordered in the 90 days prior to 2026-08-08 (plus 1,947 with partial exposure). Countries: US, UK, Sweden, Colombia, Brazil, Italy, Portugal. Trezor's public framing leads with *"our devices remain secure"* — technically true and completely beside the point. The reader-facing risk is not phishing; it is physical: confirmed crypto-holder home addresses in the hands of any buyer of the leaked data is home-invasion / stalking / $5-wrench-attack territory. Trezor firmware and devices are unaffected. See `/guides/old-iphone-cold-storage` for the shipping-address-opsec reframe + a step-by-step alternative that closes this class of exposure.

What Trezor is. Open-source-firmware hardware wallet family (Trezor One, Model T, Safe 3, Safe 5). Native Monero support via Monero GUI and Feather; the wallet holds the key, the host builds the tx, the device signs. Vendor: SatoshiLabs (Czech Republic), 12+ years of continuous operation.

Grade B rationale. The wallets themselves work well and are among the most transparent hardware in the space (fully open-source firmware, bootloader, and schematics). The B (rather than higher) reflects the recurring supply-chain and vendor-side exposure history — the 2026-08 shipping breach is the third significant PII-adjacent incident affecting Trezor customers this cycle, on top of long-standing concerns about the Trezor Suite auto-update posture. Not a firmware trust issue; a vendor-relationship + shipping-address surface issue.

What you trust. Firmware openness, well-audited cryptography, community-maintained fork ecosystem (Trezor firmware is the reference for several third-party hardware wallets), Monero GUI + Feather integration that Just Works.

What you don't. SatoshiLabs's fulfillment supply chain. Ordering to a legal-name shipping address puts you on any future breach-victim list. Mitigations: PO box, drop shipper, mail-forwarding service, or the separate-iPhone pattern in the linked guide.

Alternatives. For the airgap use case specifically: Cupcake Wallet (by the Cake Wallet team) on an old iPhone / Android — purpose-built for exactly the airgap-signer role, avoids the shipping-address surface entirely. For a hardware wallet without changing the pattern: rotate through a shipping-privacy layer before your next order.

Cross-refs. Parent guide: `/guides/monero-cold-storage`. Alternative pattern: `/guides/old-iphone-cold-storage`. Verify-your-binary: `/guides/verify-wallet-binary`.

Fees

Hardware device $69+ · Network fees only

Links

Sourced from operator pages — verify identity via more than one channel before trusting time-sensitive instructions.

Audit trail — receipts for the editorial claim

  • ● UPSTREAM Up · HTTP 200 · 48ms · checked 2h ago
  • ○ ONION No .onion mirror listed
  • ✎ MANUAL Last manual verification 2026-08-14 (<90d)

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.