Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny

Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny

N
News Editor
2026-08-14 11:06:07
Trezor disclosed on Aug. 13 that its logistics partner ShipMonk suffered unauthorized access to a system holding customer information, affecting 13,689 people. The exposed data fell into two groups: 11,742 customers had their full names, email addresses, phone numbers and full shipping addresses exposed, while 1,947 had their names, city and email addresses exposed. Trezor said its own systems, products and services were not compromised, and that hardware wallets, private keys and wallet backups were not part of the incident. The disclosure came two days after a user posted that the outer label on a domestically shipped Trezor Safe 3 package explicitly read "Trezor Safe 3 Bitcoin Only" instead of a generic product description. There is no confirmed direct link between the shipping-label complaint and the ShipMonk breach, but together they highlight the same problem: a hardware wallet may protect private keys, while purchase, fulfillment and delivery processes can still connect the device to a real-world identity. The episode has also fed a broader debate over hardware-wallet risk. Recent incidents involving Trezor, Coldcard and Ledger did not stem from the same failure point. Some relate to device or firmware security, while others involve third-party commerce, logistics or packaging exposure. For affected users, the most immediate concern is targeted phishing and social-engineering attempts that use real names, addresses, order details and device information to appear credible.
Trezordata breachhardware walletShipMonkprivacyBitcoincybersecurity

Trezor has disclosed a customer-data incident tied to its third-party logistics chain, exposing details that can link hardware-wallet purchases to real identities.

On Aug. 13, the company said its fulfillment partner ShipMonk suffered unauthorized access to a system storing customer information. Trezor said 13,689 customers were affected. Two days earlier, a user had posted a photo of a newly delivered Trezor Safe 3 package whose outer shipping label explicitly identified the contents as "Trezor Safe 3 Bitcoin Only."

There is no confirmed direct causal link between the shipping-label complaint and the later breach disclosure. The first issue involved product names printed on package labels. The second involved unauthorized access to ShipMonk systems. The Aug. 11 social-media post was not an advance leak of the later incident.

Still, the sequence has drawn attention. Before Trezor publicly disclosed the data exposure, a user had already pointed to a fulfillment process that could reveal who bought a Bitcoin hardware wallet to people who did not need to know.

What Trezor says was exposed

According to the company, ShipMonk notified Trezor on Aug. 10 that an unauthorized party had accessed a system containing customer records. When Trezor disclosed the matter publicly on Aug. 13, it said the investigation was ongoing.

Trezor said the affected population falls into two groups, totaling 13,689 customers:

  • 11,742 customers had their names, email addresses, phone numbers and full shipping addresses exposed.
  • 1,947 customers had their names, city and email addresses exposed, without detailed shipping addresses.

Trezor said the full-record exposure mainly involved customers in the U.S., the U.K., Sweden, Colombia, Brazil, Italy and Portugal whose orders were handled by ShipMonk between May 10, 2026 and Aug. 8, 2026.

The company said it requires both itself and logistics partners to delete or anonymize relevant data 90 days after an order is completed. It later added that the 1,947 customers with partial exposure may include older orders, and that it is still verifying the exact time range with ShipMonk.

Trezor said all confirmed affected customers have been contacted individually through help@trezor.io. Customers who did not receive a notification email are not within the currently confirmed scope, according to the company.

Trezor also said its own systems, products and services were not breached. Hardware wallets, private keys and wallet backups were not exposed in this incident. In other words, this was not a case of attackers breaking Trezor devices and directly draining funds. The incident sits in a third-party logistics system that held customer information.

That distinction matters. It does not remove the risk to users.

The sensitive part is not the private key, but the identity signal

A name, phone number and address cannot by themselves unlock a crypto wallet. Buying a hardware wallet also does not prove that someone still holds crypto assets, nor does it show the size of any holdings.

The problem is that those details now carry an added signal: this person bought a hardware wallet.

For scammers, accurate names, device brands, order data and home addresses can make a fraud attempt look far more convincing. An attacker can pose as Trezor, a trading platform, a bank or a courier, cite real information from the victim's order, and then push a story about a security upgrade, product recall, wallet migration or account verification to get the target to scan a QR code, install malware or hand over a seed phrase.

Email is not the only channel.

In February 2026, security outlet BleepingComputer reported that fake physical letters had been mailed to Trezor and Ledger users, asking recipients to scan QR codes for supposed identity verification or transaction checks. Those codes led to spoofed wallet websites that requested recovery phrases.

The report did not confirm which data leak supplied those home addresses. It did show that once a household address is tied to a hardware-wallet identity, phishing can move from inboxes into the physical world.

Casa co-founder Nick Neuman warned that the latest address exposure could raise the risk of targeted social engineering and even real-world coercion. Bitcoin cybersecurity specialist and Defending Bitcoin author Luke de Wolf said the compromised system belonged to a Trezor service provider, not the Trezor device itself, and suggested that buyers consider using a PO box or another non-residential delivery address when purchasing Bitcoin-related products.

Those warnings are risk assessments, not proof that every affected customer will face fraud or physical threats. Even so, a message that contains a real name, phone number, address and device information should no longer be treated as routine spam.

The shipping-label dispute points to the same exposure problem

The Aug. 11 label complaint fits the same pattern.

A Trezor user posted that the outside label on a newly delivered Trezor Safe 3 package did not use a generic product description such as "electronic device." It instead printed the full product name: "Trezor Safe 3 Bitcoin Only." The user, Angelus Borgia, said the package was shipped within the U.S. and did not involve customs declarations, prompting the question of why the full product name needed to appear on the outside at all.

Trezor says 13,689 customers were exposed in ShipMonk breach as shipping label practices draw new scrutiny 3

That means a courier, sorting staff or even neighbors who happened to see the parcel could infer that the recipient had purchased a Bitcoin hardware wallet.

A database breach requires an attacker to gain access to a system. A package marked "Bitcoin Only" exposes information during ordinary delivery. The severity is not the same, but both widen the circle of people who can learn something sensitive without any clear need to know it.

Not every hardware-wallet incident is the same

Discussion around the Trezor incident quickly expanded into a broader question: whether hardware wallets still deserve user trust.

On July 16, ZachXBT wrote on Telegram that he does not recommend using hardware wallets to store significant funds and believes a dedicated iPhone is a better option. That was his personal view on security setup.

Changpeng Zhao took a narrower line when commenting on the Trezor incident on Aug. 13. He said hardware wallets are still usually safer than software wallets in some respects, but the two categories have different risk structures. A self-custodied software wallet does not require the purchase and shipment of a physical device, so it does not create the same delivery-stage link between user identity, home address and a hardware-wallet order.

Zhao also said he was not arguing that hardware wallets are "bad," but that users should understand the trade-offs among security, privacy and convenience. Buying a hardware wallet does not prove a person still holds crypto, but that purchase record can still mark someone as a potential holder and raise phishing, social-engineering and real-world safety risks.

Even so, lumping everything into one bucket labeled "hardware wallet security incident" obscures the differences between cases. Trezor, COLDCARD and Ledger are being discussed together, but the failure points and outcomes are not the same.

The recent COLDCARD case belongs to another category. On July 30, Coinkite, the maker of Coldcard hardware wallets, issued a security notice warning that wallet seeds generated on COLDCARD Mk3 devices running certain firmware versions could be at risk. The affected range started with version 4.0.1, released in March 2021, and continued through version 5.0.3, the last release supporting Mk3. Based on Coinkite's preliminary analysis at the time, Mk4, Q and Mk5 were not affected. That issue concerned the key-generation process on the device side, which is fundamentally different from Trezor's logistics-related data exposure.

As of Aug. 7, Galaxy Research said that victim reports made it highly confident that about 1,719 BTC, worth about $111 million, had been stolen through the Coldcard hardware-wallet flaw. More suspicious funds were still being reviewed, and the total loss was expected to exceed $130 million.

Ledger's Global-e incident in January 2026 looks closer to Trezor's case. The attacked party was Ledger's third-party ecommerce partner. The exposed data included customer names, contact details and order details. Ledger said at the time that its hardware and software systems were not affected, and that payment information, passwords and recovery phrases were not exposed.

At minimum, the discussion requires three separate categories:

  • device or firmware flaws that can affect key generation, storage or transaction signing;
  • database breaches at wallet vendors or their service providers that expose customer identities and order records;
  • excessive exposure in logistics, packaging or support workflows that lets unnecessary parties see sensitive information.

What affected users can do now

First, do not assume a caller, email sender or letter is legitimate just because it contains your real name, address, phone number, order details or device model. After a leak like this, highly specific details can be the very thing that makes a scam persuasive.

Do not click unfamiliar links in security notices or scan QR codes from unknown sources. If you want updates on the incident, type Trezor's official domain manually or enter through an already verified official account. A hardware-wallet maker, a trading platform or anyone claiming to conduct a security review does not need your seed phrase to verify your identity.

Users whose home addresses were exposed should also limit how much they publicly share on social media about asset balances, location, travel plans and personal photos. If there is a direct threat, extortion attempt or suspicious in-person contact, preserve evidence and contact local law enforcement rather than dealing with the person directly.

For future purchases of hardware wallets or other sensitive security products, buyers can consider using a separate email address not tied to daily identity. Where local conditions and laws allow, pickup lockers, mailboxes or other non-residential delivery points can also reduce the direct link between a home address and a product order.

Trezor said it is developing an "anonymous delivery" service with a dedicated checkout flow, pickup lockers, neutral packaging, anonymous sender information and automatic deletion of related identifiers after delivery. The target is to launch the service in the EU in September 2026 and expand it to the U.S. before year-end.

Security starts before the device is switched on

The incident shows that security does not begin only when a user first powers on a wallet.

If the outside of a parcel says "Bitcoin Only," and if a logistics database can tie a name, phone number and home address to a hardware-wallet order, the user's security perimeter has already moved outward even when the private key inside the device has never been exposed.

For a company that sells tools for financial self-sovereignty, collecting less data, retaining less data and letting fewer people know who bought what should be treated as part of product security too.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.