Trezor built its reputation on a simple promise: the company never holds your keys, so a breach at Trezor cannot empty your wallet. On 13 August 2026 it had to lean on that promise in the worst possible circumstances, announcing that a shipping partner had leaked the names, email addresses, phone numbers and home addresses of nearly 14,000 people who recently bought its hardware wallets.
The company at fault is ShipMonk, a fulfilment provider that packs and posts Trezor orders. Attackers got into ShipMonk's systems and came away with order data for customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, covering roughly the three months of orders before the intrusion was found.
Set against the mega-breaches of recent years, 13,689 people is a small number. What makes this one nasty is the audience. A leaked list of hardware wallet buyers is not a marketing database; it is a pre-qualified register of people who very probably hold cryptocurrency, paired with exactly where they live and how to reach them.
What happened, and when
The timeline is short. ShipMonk told Trezor on 10 August 2026 that an unauthorised party had accessed systems holding customer order data, and Trezor published its disclosure three days later, on 13 August. The exposed records cover orders fulfilled between 10 May and 8 August 2026, so at worst the data describes purchases barely a week old.
The intrusion route ran a layer deeper than the shipping firm itself. BleepingComputer reports that ShipMonk's notification to its own customers blamed a vulnerability in Metabase, an analytics tool running inside ShipMonk's environment, and that Metabase has since described the flaw as a critical SQL injection zero-day. The chain is worth spelling out: a bug in an analytics product, exploited at a logistics company, exposed the customers of a security company. Nobody along that chain chose its weakest link. They inherited it.
No Trezor system, product, or service was affected, and our operations continue as normal.
That line from Trezor's statement is true and worth having: wallets, firmware and recovery seeds were untouched, and nothing in the stolen data can move funds on its own. It is also, for the people on the list, not the whole story. Trezor concedes as much, warning that affected customers "might be targeted by more sophisticated phishing attempts". As of 13 August, CoinDesk reported, the company had seen no sign of the data being published, sold or used in scams. That is how these stories usually begin, not how they end.
What leaked
Trezor's own statement is precise about the two groups of affected customers, which makes a change from the vague "certain information" phrasing that pads most disclosure letters.
| Group | People | Data exposed |
|---|---|---|
| Full order records | 11,742 | Name, email, phone number, shipping address |
| Partial records | 1,947 | Name, city, email |
In total that is 13,689 people. The disclosure lists contact and shipping data and nothing else; payment details, passwords and identity documents go unmentioned, and a recovery seed never leaves the device, so the absence Trezor most wants noticed is genuine: nothing here unlocks a wallet. What the dataset does provide is everything required to impersonate Trezor convincingly, aimed at exactly the people most worth impersonating. A list of confirmed hardware wallet buyers, with home addresses attached, is about as targeted as stolen data gets.
The email address deserves particular attention, because it is the one field that keeps working after everything else goes stale. People move house and change phone numbers; an email address tends to follow its owner for a decade or more, and each one in this file now carries a permanent annotation that its owner bought a hardware wallet in the summer of 2026. The shipping labels will age out of usefulness. That pairing will not, which is why the file will keep changing hands long after this news cycle closes.
Working out whether you are affected
Trezor says the affected orders shipped between 10 May and 8 August 2026 to one of the seven countries above. If that describes a purchase of yours, the safe assumption is that your details are in the set; most of the records, 11,742 of them, are the complete version with phone number and street address.
Whether the data ever surfaces in Have I Been Pwned depends on whether the attackers publish it, so a clean result there proves nothing for now. Our guide to reading a Have I Been Pwned result covers what the service can and cannot tell you. In the meantime, take Trezor's advice about official channels literally: reach the company by typing its address yourself, never through a link in a message that found you first.
What to do now
The general playbook for a leaked address is in our checklist for when your email leaks. The Trezor-specific version sharpens to five points.
- Treat every message that mentions Trezor, ShipMonk or your order as hostile until proven otherwise, whether it arrives by email, text, phone call or post.
- Never type your recovery seed into anything. Not a website, not an app, not a "validation tool". Trezor's own instruction is blunt: "Never enter your wallet backup on a website or share it with anyone."
- Expect the phishing to be specific. Attackers know your name, your address and roughly when you bought. A message quoting all three is not proof of legitimacy; it is now the baseline.
- Be sceptical of physical mail and phone calls too. The people holding this data know where you live, and a courier-sized dataset invites courier-themed scams.
- If the leaked address is one you reuse everywhere, start moving your most sensitive logins onto addresses that do not appear in breach dumps. The exchange account that shares an address with your Trezor order is the obvious first candidate, because that address is now firmly associated with cryptocurrency.
The pattern it repeats
Nothing about this incident is novel, which is exactly the problem. It is the second breach in a matter of days in which a logistics contractor spilled data belonging to a company whose own security held: last time it was CEVA Logistics and Steam, this time it is ShipMonk and Trezor. Physical products need shipping, shipping needs a fulfilment partner, and the partner needs your name, address, email and phone number to do its job. Every hop duplicates the data, and the copy with the weakest defences sets your odds.
Trezor has been here before, too. A breach at its third-party support portal in January 2024 exposed contact details of some 66,000 users, and CoinDesk's reporting on the current incident counts an earlier compromise in 2022 that reached 106,856 customer records. The company's devices have never been the problem. The orbit of ordinary services around them keeps being one.
The crypto-hardware sector has already run this experiment at scale. After Ledger's e-commerce database leaked in 2020, customers endured years of aftermath, from relentless seed phrase phishing to tampered "replacement" devices posted to victims' homes. That is the playbook Trezor's 13,689 should now expect, and Trezor's one-line defence, never enter your wallet backup anywhere, is the single habit that defeats all of it.
For everyone else, the transferable lesson is about blast radius. You cannot audit your retailer's fulfilment partner, let alone the analytics software running inside it. What you can control is what a single vendor's failure costs you. A unique email address per merchant means the leaked copy names the company that lost it and can be retired on the spot; a shared address, especially one attached to financial accounts, turns someone else's breach into your standing liability.