Skip to content
CUNICULA

Trezor

Multi-coin hardware signer with an open source firmware and crypto checkout.

trezor.io

Multi-coin hardware signer with an open source firmware and crypto checkout.

Common useCold storageWalletOperator dataHosted
Identity checksZero KYCNo document check recorded · identity exposure level 2/4
Evidence and riskVerified evidenceCautionMaterial claims checked against current sources.; those sources show trade-offs worth reading.
Last reviewedReviewed 23 Aug 2026KYC checked 7 Aug 2026 · verified jurisdiction · Source → official siteHow to cite this pageSource coverageVerified evidenceRecorded riskCaution
Evidence and facts

Evidence and facts

CUNICULA SCORE 4.0
26/100Limited evidencePrivacy 6/25 · Control 0/20 · Transparency 0/20 · Security 12/25 · Accountability 8/10 · Cap 39 · Method
JURISDICTIONCZ
INCIDENTBrevo newsletter export and fraudulent STM32 email
active · high · since 2026-09-09
Trezor's September 17, 2026 update reports 347,149 newsletter email addresses exported through Brevo. The September 9 message headed 'Critical Security Alert: STM32 Entropy Vulnerability' was phishing: its app requested a wallet backup, not a genuine hardware repair. Trezor says no product, wallet or account system was affected and no passwords or wallet data were held in this list. Brevo says the messages passed email authentication, and attacker access is closed; active here means residual phishing exposure. Do not follow the email links or disclose a backup; delete the message. If a backup was entered, Trezor directs an immediate transfer to a new wallet using its official guide. A firmware update does not undo contact-data exposure. Sources checked September 21, 2026. Trezor disclosure, updated September 17, 2026, Brevo September 10 postmortem, Trezor: moving funds after backup exposure (checked September 21)
INCIDENTShipMonk shipping data and historical-order exposure
active · high · since 2026-08-10
Trezor's September 4, 2026 update reports 80,689 affected customers in the ShipMonk incident, including approximately 67,000 additional US customers with November 2019 to August 2021 orders. Exposed fields include names, emails, phone numbers, shipping addresses and order numbers; 1,947 customers had partial name/city/email exposure. Trezor says old data remained despite written deletion assurances, its own systems and devices were not compromised, and ShipMonk secured its systems. Active here means residual data exposure, not a continuing intrusion. Address exposure can support fraudulent calls, letters and physical targeting; accurate order details do not authenticate a message. Never share a wallet backup and verify communications through the official site. This population may overlap with Brevo's contacts: do not add the totals. Sources checked September 21, 2026. Trezor ShipMonk disclosure, updated September 4, 2026
INCIDENTUnauthorized newsletter email
resolved · high · since 2024-01-24
An unauthorized actor used a separate third-party email service to send Trezor newsletter subscribers an unauthorized newsletter email asking for recovery seeds. Trezor said the event affected newsletter email addresses only, deactivated the link, and restricted unauthorized access. No device, recovery seed, wallet, or funds compromise was reported. Trezor newsletter security alert
INCIDENTThird-party support portal contact exposure
resolved · high · since 2024-01-17
Unauthorized access to Trezor's third-party support-ticket portal may have exposed the name/nickname and email address of up to 66,000 support contacts. Phishing followed: the actor emailed 41 users asking for recovery-seed information. No device, recovery seed, wallet, or funds compromise was reported. Trezor support portal security update, Trezor newsletter security alert
AUDITED BYNo audit listed
OPERATOR DATAHosted operator recorded
SOURCE COVERAGE
Verified evidenceTHIRD-PARTY REPORTED3/14Reviewed 23 Aug 2026 · Source → official site
LAST CHECKED2026-08-23
LAST UPDATED2026-09-21

Specs

DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 2/4
KYC TRIGGERSNo document identity check is required to buy a device. The shop states it supports Google Pay, Apple Pay, debit and credit card, Bitcoin, and selected cryptocurrencies. Paying with Bitcoin removes the card trail but a delivery address is still recorded, and the shop ships to over 200 countries and territories.
FEEFrom EUR 47 (one-time hardware)
NETWORKSBTC, ETH, LTC
CATEGORIESWallet
COMMON USESCold storage, Multi-coin self-custody, Buying hardware without an account
FEATURESMulti-coin hardware signer, Bitcoin-only firmware option, Open source firmware, Secure Element on Safe models, PIN and passphrase, On-device confirmation, Coin control in Trezor Suite, Tor support in Trezor Suite, +1 more
TORYes
REGIONSGlobal availability
Review analysis, source material, related services, and history

About

Czech hardware wallet vendor. The shop accepts Bitcoin, Litecoin, and Ethereum alongside cards and PayPal, and ships worldwide.

Corporate identity

Registry-sourced, not audited. The facts below come from cited web research rather than a direct registry query. Each claim links its own source.

LEGAL ENTITY
Trezor Company s.r.o.source ↗
REGISTRATION NO.
02440032source ↗
INCORPORATED IN
Czech Republicsource ↗
INCORPORATED ON
2013-12-12source ↗
REGISTERED ADDRESS
Kundratka 2359/17a, Libeň, 180 00 Prague 8, Czech Republicsource ↗
Registry research · reviewed 2026-08-08

Ownership chain

Who owns the operator, read from the public register. Each step says what kind of evidence it rests on: a registry record can be checked, a company statement cannot.

  1. OPERATORTrezor Company s.r.o.02440032 · Czech Republic
  2. SHAREHOLDERSatoshiLabs Group a.s.08685916 · Czech Republic82.5%REGISTRY RECORDsince 2026-04-09

    The Czech commercial register lists SatoshiLabs Group a.s. (IČO 08685916) as holder of an 82.5% share in Trezor Company s.r.o., entered 2026-04-09 and not struck.

    The remaining 17.5% is held by four named individuals at 5%, 5%, 5% and 2.5%. Czech law publishes the shareholders of a s.r.o., which is why this chain is visible at all; the equivalent Swiss and Swedish holdings are not public in the same way. The holding was 96.5% between 2023-11-24 and 2026-04-09.

    ARES full commercial register record for IČO 02440032

The chain stops here because the register stops, not because the top was reached. Swiss and Swedish companies do not publish their shareholders, and a Czech joint-stock company does not list its own. Nothing above the last step should be assumed either way.

WHAT IT USED TO BE
  • SatoshiLabs s.r.o.renamed 2021-09-30REGISTRY RECORD

    The company register records this name from incorporation on 2013-12-12 until it was struck on 2021-09-30, when Trezor Company s.r.o. was entered against the same IČO.

Frequently Asked Questions

Is identity verification required?

No identity verification is recorded for typical use. No document identity check is required to buy a device. The shop states it supports Google Pay, Apple Pay, debit and credit card, Bitcoin, and selected cryptocurrencies. Paying with Bitcoin removes the card trail but a delivery address is still recorded, and the shop ships to over 200 countries and territories.

Which payment methods are accepted?

Accepted payment methods: BTC, ETH, LTC.

Where is it available?

Recorded availability: GLOBAL.

Is the operator based in a Five Eyes country?

No. The recorded jurisdiction is CZ, which is not a Five Eyes country. This is jurisdiction context and does not by itself establish that a service is safer or less safe.

How are identity, operator, and evidence fields reported?

Identity exposure is level 2 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-08-23, and recorded risk is caution.

Which payment networks are supported?

Accepted networks: BTC, ETH, LTC.

Related Services

Sources and history

Terms and privacy policy

No changes to the document we watch since we started checking on 9 Aug 2026. Last checked 9 Aug 2026.

Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.