Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 16, 2026 · 6 min read

Trezor Partner Breach Exposed 13,689 Customers

ShipMonk told Trezor on August 10 that someone had reached systems holding order data. The wallets are fine and the keys were never at risk. What leaked is the list of people who bought one, and the addresses those packages went to.

There is a reason people buy a hardware wallet under a nickname, ship it to a work address, or have it sent to a pickup point. The device itself is a lump of secure silicon that gives up nothing. The fact that you own one is the sensitive part, and that fact does not live inside the device. It lives in a fulfilment database, next to your street address.

Key Takeaways

  • Trezor says approximately 13,689 customers were affected by unauthorised access at ShipMonk, the fulfilment provider that ships its hardware wallets.
  • 11,742 of those customers had full name, email address, phone number and shipping address exposed; 1,947 had name, city and email address exposed.
  • ShipMonk notified Trezor on Monday, August 10, 2026, and the affected orders were delivered between May 10 and August 8, 2026.
  • Customers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal are in scope; Trezor states its own systems, devices, private keys and wallet backups were not affected.
  • Trezor credits a 90 day data storage policy, which requires partners to delete or anonymise order data 90 days after delivery, for limiting the exposure window.

What Actually Happened?

A third party got into systems at ShipMonk, the logistics company that packs and ships Trezor orders. ShipMonk informed Trezor on August 10, and Trezor published its own notice naming the number of affected customers and the exact fields involved rather than the usual "certain personal information" formulation.

Nothing was taken from Trezor. No firmware was touched, no seed phrase existed anywhere to take, and the wallets in customers' hands are exactly as secure as they were the day before. That distinction is real and worth stating plainly, because the crypto world's reflex on hearing "Trezor breach" is to assume funds are at risk. They are not, and no mechanism in this incident could put them at risk on its own.

The harm here runs through people, not code. This is the same shape as the CEVA Logistics intrusion that hit Steam hardware buyers and the Amgen breach that lived entirely in third party clouds: the brand on the box never got compromised, and its customers were exposed anyway.

Who Is Affected and What Exactly Leaked?

Two groups, with different exposure. 11,742 customers had the full set: name, email address, phone number and shipping address. Another 1,947 had a partial record of name, city and email address. Together that is roughly 13,689 people whose orders were delivered between May 10 and August 8, 2026, across the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.

Read the two tiers as two different problems. The partial group is a phishing list: someone knows you bought a Trezor and knows your city. The full group is a phishing list with a doorstep attached. Coverage from crypto.news and others has focused on the phishing angle, which is the likely outcome for almost everyone. The physical risk is far less likely and far worse, and it is the reason a shipping list for this product is not comparable to a shipping list for headphones.

An opened cardboard shipping box with crumpled packing paper on a dark wooden table, a small dark device resting beside it, a front door visible in the background

Why Is a Shipping List Worse Than a Password Leak?

Because you can change a password and you cannot change the fact that a package arrived at your house.

A hardware wallet purchase is a statement of intent. It says the buyer holds enough cryptocurrency to justify dedicated hardware, and that they self custody rather than leaving it on an exchange. Self custody means there is no support desk to freeze the account and no chargeback if the funds move. A list that says "these 11,742 named people at these street addresses recently bought self custody hardware" is a qualified lead list for exactly the crime that has no reversal.

The email version arrives first and arrives dressed as the vendor. Fake support messages, fake firmware update notices, fake "your device has been flagged" alerts, all pointing at a page that asks for the recovery seed. We covered a near identical play against a competing wallet brand when a fake COLDCARD security audit email installed a remote access tool. Those campaigns work far better when the sender already knows your name, your phone number and the month your device shipped.

Did the 90 Day Retention Policy Actually Help?

Yes, and it is the most useful detail in the whole disclosure.

Trezor requires its fulfilment partners to delete or anonymise order data 90 days after delivery. That is why a company shipping wallets worldwide for years reported a three month window of orders rather than a decade of them. The same intrusion at a vendor with default retention, which in practice means forever, would have produced a file with hundreds of thousands of names in it instead of 13,689.

This is the argument for data minimisation stated in numbers rather than in principle. Nobody prevents every vendor intrusion. What you can decide in advance is how much is sitting there when one happens, and that decision is made months earlier by whoever wrote the retention clause into the contract.

What Should Trezor Customers Do Now?

  • Treat every Trezor branded message as hostile until proven otherwise. Do not click links in wallet related mail. Type trezor.io yourself, or open Trezor Suite directly, and check for the notice there.
  • Never enter your recovery seed anywhere. No genuine support process, firmware update, migration, or verification ever asks for it. A request for the seed is definitive proof of fraud, no matter how convincing everything around it looks.
  • Expect phone calls, not just email. Phone numbers leaked for 11,742 people. A caller who knows your order is not verified by that knowledge. Hang up and reach support through the vendor's own site.
  • Consider a passphrase. A wallet passphrase, held only in your head, means a stolen device or a coerced backup does not reach the funds. This is the specific mitigation for the physical scenario the address leak creates.
  • Watch what your inbox reveals back. Scam mail sent to a leaked list is loaded with tracking that confirms your address is live and that you read the message, which promotes you to a shorter and more aggressive list. Our guide to detecting email tracking pixels in Gmail shows what a message reports back the moment it renders.
  • Assume the follow up wave is automated. Extortion mail quoting a real home address has followed every leak of this shape this year. We explained why the accurate personal details prove nothing.

The Part Worth Remembering

Trezor's security model held perfectly and 13,689 customers still got hurt, because the threat model of a hardware wallet stops at the edge of the device and the buyer's exposure does not. Between the checkout page and the doorstep sits a fulfilment provider, a courier, a payment processor and a support tool, each holding a copy of who you are and where you live.

The lesson is not that hardware wallets are unsafe. It is that buying privacy hardware through an ordinary supply chain leaves an ordinary paper trail, and that the trail is now the softest target in the transaction. Retention limits shrink it. Nothing removes it.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.