Trezor Says Shipping Partner Breach Exposed Data of Nearly 14,000 Hardware Wallet Customers

Hardware wallet maker Trezor disclosed that one of its shipping providers was breached, exposing customer order data for thousands of buyers. The company's devices and wallet infrastructure were not touched, but the leak hands attackers exactly the kind of information used in phishing campaigns and physical targeting of Bitcoin holders.
WHAT HAPPENED
"On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," Trezor said. The incident did not touch Trezor infrastructure, wallets, or firmware, but it did expose personal details that scammers can weaponize in social engineering campaigns.
WHO IS AFFECTED
The breach affected roughly 13,689 customers who received orders between May 10 and August 8, 2026. Of those, 11,742 customers had full exposure of name, email address, phone number and shipping address, while 1,947 had partial exposure limited to name, city and email. Impacted shipments were tied to destinations including the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said the scope stayed relatively contained because of its strict 90-day data retention policy, which also applies to fulfillment partners.
WHAT TREZOR IS TELLING CUSTOMERS TO DO
Trezor stated that its systems were not compromised and that customer devices remain secure, and that hardware wallets, private keys and wallet backups were not affected. The company told customers to treat any communication that demands immediate action or requests personal information as suspicious, to check claims against official channels, and to never enter a wallet backup on a website or share it with anyone. Affected customers were also contacted individually by email, and Trezor is warning that people whose home addresses leaked should be especially alert, since that detail has been used in prior industry breaches to enable so called wrench attacks targeting Bitcoin holders in person.
THE BROADER SELF-CUSTODY SQUEEZE
This breach lands in the middle of a rough stretch for hardware wallet security more broadly. A separate $116 million Coldcard hardware wallet exploit already rattled the self-custody community this month. On the show, the hosts also pointed to a Lightning-related outage at Boltz and a vulnerability disclosure affecting BTCPay Server as part of the same rough patch for self-custody infrastructure, though those specific claims are attributed to the show's own reporting rather than independently confirmed here. Trezor said it is accelerating an "Anonymous Delivery" option, with locker pickup, neutral packaging and generic sender details, targeting the EU by September 2026 and the US by the end of 2026, an approach aimed at breaking the link between a customer's name and the address a hardware wallet gets shipped to in the first place.
None of this changes the underlying math on self-custody. It does argue for diversifying how a stack is stored and shipped rather than concentrating everything in one wallet tied to one home address.
This story comes from the Simply Bitcoin Live show. Watch the full episode.

