Breach analysis · 6 min read

Trezor's Shipping Breach Exposes 13,689 Wallet Buyers

ShipMonk's breach leaked names, emails and home addresses of nearly 14,000 Trezor buyers. What got out, and why wallet owners are prime phishing targets.

YeyMail Team ·

Trezor built its reputation on a simple promise: the company never holds your keys, so a breach at Trezor cannot empty your wallet. On 13 August 2026 it had to lean on that promise in the worst possible circumstances, announcing that a shipping partner had leaked the names, email addresses, phone numbers and home addresses of nearly 14,000 people who recently bought its hardware wallets.

The company at fault is ShipMonk, a fulfilment provider that packs and posts Trezor orders. Attackers got into ShipMonk's systems and came away with order data for customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, covering roughly the three months of orders before the intrusion was found.

Set against the mega-breaches of recent years, 13,689 people is a small number. What makes this one nasty is the audience. A leaked list of hardware wallet buyers is not a marketing database; it is a pre-qualified register of people who very probably hold cryptocurrency, paired with exactly where they live and how to reach them.

What happened, and when

The timeline is short. ShipMonk told Trezor on 10 August 2026 that an unauthorised party had accessed systems holding customer order data, and Trezor published its disclosure three days later, on 13 August. The exposed records cover orders fulfilled between 10 May and 8 August 2026, so at worst the data describes purchases barely a week old.

The intrusion route ran a layer deeper than the shipping firm itself. BleepingComputer reports that ShipMonk's notification to its own customers blamed a vulnerability in Metabase, an analytics tool running inside ShipMonk's environment, and that Metabase has since described the flaw as a critical SQL injection zero-day. The chain is worth spelling out: a bug in an analytics product, exploited at a logistics company, exposed the customers of a security company. Nobody along that chain chose its weakest link. They inherited it.

No Trezor system, product, or service was affected, and our operations continue as normal.

That line from Trezor's statement is true and worth having: wallets, firmware and recovery seeds were untouched, and nothing in the stolen data can move funds on its own. It is also, for the people on the list, not the whole story. Trezor concedes as much, warning that affected customers "might be targeted by more sophisticated phishing attempts". As of 13 August, CoinDesk reported, the company had seen no sign of the data being published, sold or used in scams. That is how these stories usually begin, not how they end.

What leaked

Trezor's own statement is precise about the two groups of affected customers, which makes a change from the vague "certain information" phrasing that pads most disclosure letters.

GroupPeopleData exposed
Full order records11,742Name, email, phone number, shipping address
Partial records1,947Name, city, email

In total that is 13,689 people. The disclosure lists contact and shipping data and nothing else; payment details, passwords and identity documents go unmentioned, and a recovery seed never leaves the device, so the absence Trezor most wants noticed is genuine: nothing here unlocks a wallet. What the dataset does provide is everything required to impersonate Trezor convincingly, aimed at exactly the people most worth impersonating. A list of confirmed hardware wallet buyers, with home addresses attached, is about as targeted as stolen data gets.

The email address deserves particular attention, because it is the one field that keeps working after everything else goes stale. People move house and change phone numbers; an email address tends to follow its owner for a decade or more, and each one in this file now carries a permanent annotation that its owner bought a hardware wallet in the summer of 2026. The shipping labels will age out of usefulness. That pairing will not, which is why the file will keep changing hands long after this news cycle closes.

Working out whether you are affected

Trezor says the affected orders shipped between 10 May and 8 August 2026 to one of the seven countries above. If that describes a purchase of yours, the safe assumption is that your details are in the set; most of the records, 11,742 of them, are the complete version with phone number and street address.

Whether the data ever surfaces in Have I Been Pwned depends on whether the attackers publish it, so a clean result there proves nothing for now. Our guide to reading a Have I Been Pwned result covers what the service can and cannot tell you. In the meantime, take Trezor's advice about official channels literally: reach the company by typing its address yourself, never through a link in a message that found you first.

What to do now

The general playbook for a leaked address is in our checklist for when your email leaks. The Trezor-specific version sharpens to five points.

  • Treat every message that mentions Trezor, ShipMonk or your order as hostile until proven otherwise, whether it arrives by email, text, phone call or post.
  • Never type your recovery seed into anything. Not a website, not an app, not a "validation tool". Trezor's own instruction is blunt: "Never enter your wallet backup on a website or share it with anyone."
  • Expect the phishing to be specific. Attackers know your name, your address and roughly when you bought. A message quoting all three is not proof of legitimacy; it is now the baseline.
  • Be sceptical of physical mail and phone calls too. The people holding this data know where you live, and a courier-sized dataset invites courier-themed scams.
  • If the leaked address is one you reuse everywhere, start moving your most sensitive logins onto addresses that do not appear in breach dumps. The exchange account that shares an address with your Trezor order is the obvious first candidate, because that address is now firmly associated with cryptocurrency.

The pattern it repeats

Nothing about this incident is novel, which is exactly the problem. It is the second breach in a matter of days in which a logistics contractor spilled data belonging to a company whose own security held: last time it was CEVA Logistics and Steam, this time it is ShipMonk and Trezor. Physical products need shipping, shipping needs a fulfilment partner, and the partner needs your name, address, email and phone number to do its job. Every hop duplicates the data, and the copy with the weakest defences sets your odds.

Trezor has been here before, too. A breach at its third-party support portal in January 2024 exposed contact details of some 66,000 users, and CoinDesk's reporting on the current incident counts an earlier compromise in 2022 that reached 106,856 customer records. The company's devices have never been the problem. The orbit of ordinary services around them keeps being one.

The crypto-hardware sector has already run this experiment at scale. After Ledger's e-commerce database leaked in 2020, customers endured years of aftermath, from relentless seed phrase phishing to tampered "replacement" devices posted to victims' homes. That is the playbook Trezor's 13,689 should now expect, and Trezor's one-line defence, never enter your wallet backup anywhere, is the single habit that defeats all of it.

For everyone else, the transferable lesson is about blast radius. You cannot audit your retailer's fulfilment partner, let alone the analytics software running inside it. What you can control is what a single vendor's failure costs you. A unique email address per merchant means the leaked copy names the company that lost it and can be retired on the spot; a shared address, especially one attached to financial accounts, turns someone else's breach into your standing liability.

The YeyMail takeaway
The vendor you never chose

Trezor's security held; a contractor's analytics tool did not, and 13,689 customers carry the consequences. You cannot vet every company your data passes through, but you can decide how much any one of them can lose. YeyMail gives every shop its own alias, so when a vendor leaks, the exposed address tells you exactly who lost it, and the kill switch refuses further mail at SMTP time. The kill switch is never paywalled and keeps working even if you cancel. Starter is $0.99/month, and there is a free 7-day trial with no card required.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Can anyone steal my crypto with the leaked Trezor data?

Not directly. The leak contains names, email addresses, phone numbers and shipping addresses; the disclosure mentions no passwords or payment details, and a recovery seed never leaves the device. Funds move only with your seed or your device and PIN. The real risk is phishing that persuades you to hand the seed over yourself.

How do I know if I am in the Trezor breach?

Trezor says the exposed records cover orders shipped between 10 May and 8 August 2026 to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. If you ordered in that window to one of those countries, assume your details are included and treat incoming messages accordingly.

Was Trezor itself hacked?

No. The breach happened at ShipMonk, a fulfilment provider that ships Trezor orders, and Trezor states that no Trezor system, product or service was affected. BleepingComputer reports that ShipMonk attributed the intrusion to a vulnerability in Metabase, an analytics tool, later described as a critical SQL injection zero-day.

What will phishing after this breach look like?

Expect messages that use your real name, address and order timing to look legitimate: fake security alerts, firmware update prompts, or requests to validate your wallet. Some may arrive by phone or post rather than email. Anything that asks for your recovery seed is an attack, without exception.

Do I need to replace my Trezor device?

No. The device and its firmware were not involved, and Trezor says wallets remain secure. Be wary of the opposite scenario instead: after Ledger's 2020 leak, scammers sent tampered replacement devices to victims. A device you did not order is not a gift.

Keep reading

Breach analysis
Steam Hardware Buyers Caught in the CEVA Logistics Breach
Breach response
Your Email Was Leaked: The Complete What-Now Checklist
Breach response
Have I Been Pwned: How It Works and What Results Mean