August 13, 2026: Hardware wallet maker Trezor confirmed that fulfillment partner ShipMonk suffered unauthorized access exposing order data for 13,689 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Official notice: trezor.io blog. Canonical record: trezor-shipmonk2026.
Trezor says its own systems, devices, private keys, and wallet backups were not compromised. The risk is real-world: home addresses and phones in the hands of people who know you bought a hardware wallet.
What happened
On August 10, 2026, ShipMonk told Trezor that an unauthorized party accessed systems holding customer data. Trezor published customer emails and a public blog on August 13. Orders delivered roughly May 10–August 8, 2026 in seven countries sit in scope for the main exposure set, constrained by Trezor’s negotiated 90-day retention with fulfillment partners.
BleepingComputer reported that ShipMonk’s customer notices attribute the intrusion to a vulnerability in third-party analytics platform Metabase, with Metabase notifying ShipMonk around August 6 that an unauthorized party exploited software to access account/customer-related data. That vendor path is separate from Trezor’s product stack.
What data was exposed
- 11,742 customers — full exposure: name, email, phone, shipping address
- 1,947 customers — partial exposure: name, city, email (Trezor later noted this subset may include some older orders and is verifying with ShipMonk)
- Order numbers included in the logistics dataset
Not exposed per Trezor: device firmware integrity, seed phrases/wallet backups, private keys, and Trezor corporate systems.
Why address leaks hurt hardware-wallet buyers
Crypto phishing after Ledger’s historical e-commerce leaks trained attackers to combine “you own a cold wallet” with urgent seed-phrase lures. Full shipping addresses raise the stakes further: postal letters, courier impersonation, and physical targeting become plausible. Community replies calling this “IRL phishing” are not hyperbole—knowing a household ordered a Trezor is valuable to thieves even when the device itself remains cryptographically sound.
Trezor warned of fake emails, phone calls, and letters impersonating banks, exchanges, or Trezor itself. Never enter a recovery phrase on a website. Never share it with “support.” Verify only via bookmarked trezor.io channels and the [email protected] notice thread.
Who is at risk
New customers in the seven named countries who received shipments in the May 10–August 8 window (plus anyone who received Trezor’s [email protected] notification). Older orders were largely out of ShipMonk’s retained set because of the 90-day delete/anonymize policy—though Trezor flagged uncertainty around the partial-exposure cohort.
What Trezor and ShipMonk said
Trezor apologized, said investigation continues, and promised blog updates. It is building an Anonymous Delivery option (locker pickup, neutral packaging, generic sender, auto-delete of shipping identifiers)—targeting EU readiness around September and US later in 2026. ShipMonk reportedly secured affected systems and holds SOC 2 Type II certification (which did not prevent this incident).
Action items
- Check inbox for mail from [email protected] about this incident.
- Treat any seed-phrase, “device sync,” or urgent wallet-migration request as a scam.
- Do not click shipping/customs fee links that cite your real address.
- Consider PO Box / anonymous email for future hardware orders; watch for Anonymous Delivery rollout.
- Enable physical-security awareness at home if your full address was in the full-exposure set.
- Rotate reused email passwords if the same mailbox guards exchange accounts.
- Report impersonation attempts to Trezor via official support only.
- Ignore “Ledger+Trezor merger” or similar recovery-phrase phishing themes recycled from prior vendor leaks.
Industry context
Third-party fulfillment and payment partners remain the soft underbelly of hardware-wallet retail—Ledger’s Global-e / historical e-commerce incidents set the template. August 2026 also saw CEVA Logistics ripples into Valve/Steam hardware notices; Trezor’s case is a different vendor (ShipMonk) via Metabase, not CEVA. BreachHistory indexes both logistics waves separately.
Timeline
Public reconstruction from Trezor and ShipMonk notices runs roughly as follows. Around August 6, Metabase informed ShipMonk that an unauthorized party exploited a vulnerability to reach data related to ShipMonk’s account and customers. ShipMonk investigated, secured systems, and on August 10 notified Trezor of unauthorized access to systems holding customer records. Trezor notified affected buyers and published its blog and X thread on August 13, defining the primary order window as May 10–August 8, 2026 across seven countries.
That sequence matters for phishing triage: scammers often move within hours of a public crypto-vendor disclosure. If you received a [email protected] mail on the 13th and a “urgent seed migration” mail on the 14th, the second one is almost certainly hostile.
Metabase as the reported entry path
ShipMonk’s notices, as summarized by BleepingComputer, point to a Metabase analytics vulnerability rather than a ransomware encryptor on Trezor’s shop. Metabase SQLi / data-theft campaigns against customer deployments were already in 2026 trade press. Fulfillment companies wire analytics tools into operational databases; when those tools are patch-lagged or internet-exposed, parcel datasets become collateral.
For other brands using ShipMonk, treat Trezor’s disclosure as a cue to ask whether your tenancy was in the same Metabase exposure—not as automatic proof you were. ShipMonk has not published a global multi-brand census in the sources reviewed for this indexing.
How this differs from Ledger’s Global-e incidents
Ledger buyers lived through e-commerce and payment-partner leaks that flooded inboxes with fake recovery flows. Trezor’s ShipMonk case rhymes: third-party logistics/payment adjacency, order PII out, device crypto intact. Differences include scale (tens of thousands vs historical Ledger million-scale email sets), the explicit 90-day retention that capped ShipMonk’s retained set, and Trezor’s promise of Anonymous Delivery with locker pickup and neutral packaging.
Do not assume “Trezor was safer because the number is smaller.” Full street addresses for hardware-wallet owners are high-signal even at 11,742 fully exposed households.
Physical and social-engineering playbooks to expect
- Courier SMS: “customs fee for your Trezor shipment” with a payment link
- Letters on fake SatoshiLabs letterhead asking you to “re-verify” a device
- Voice calls claiming support needs your 24-word backup to “secure” the wallet after the breach
- Exchange impersonation: “we see a Trezor withdrawal—confirm seed to unlock”
- Neighbor/doorstep pretexting if an address is in the full-exposure set
None of those require cracking the Secure Element. They require fear and urgency. Slow down. Hang up. Use bookmarks.
Privacy options Trezor recommends
Trezor’s FAQ suggests anonymous email at checkout, PO Boxes where practical (with USPS identity caveats), and forthcoming Anonymous Delivery with dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery—EU targeted around September 2026, US later. Those options do not erase the current leak for people already notified; they reduce recurrence.
Was I affected?
If you ordered to one of the seven countries and got a parcel between May 10 and August 8, 2026, check for mail from [email protected]. Trezor says notification recipients were in the exposed set. Partial-exposure customers (name/city/email) should still assume phishing risk even without a full street address in the dump Trezor described.
Searching “Trezor data breach 2026,” “Trezor ShipMonk,” or “Trezor shipping provider incident” should lead to the official blog—not to lookalike domains harvesting seeds.
Prior Trezor third-party incidents (context)
CryptoPotato and BleepingComputer situate this as the first Trezor-linked exposure of phones and shipping addresses since founding, while noting earlier third-party hits: a 2022 Mailchimp-related phishing wave and a 2024 support-portal exposure affecting roughly 66,000 support users’ names/emails. Pattern recognition for customers: the brand’s cold-wallet cryptography can be fine while marketing, support, and logistics vendors remain soft targets.
Action items for exchanges, family offices, and high-balance holders
- Brief household members who might answer the door or phone about courier scams.
- Prefer withdrawal allowlists and time delays on exchanges so a panicked “support” call cannot drain funds.
- Store seed backups offline; never photograph them “for support.”
- If your address was fully exposed, review physical security and package-theft habits for weeks after disclosure.
- Corporate buyers: route future hardware through office receiving with minimal home-address use.
- Security teams at other ShipMonk customers: open a vendor ticket asking about Metabase exposure scope.
- Document the notification email headers for insurance or incident files.
- Ignore secondary “breach check” websites that ask for seed phrases or wallet passwords.
Bottom line
The Trezor ShipMonk data breach is a confirmed third-party fulfillment incident: 13,689 customers, heavy address exposure for most of them, devices still secure per Trezor, phishing and physical-pretext risk elevated. Treat official Trezor channels as the only source of truth, and assume scammers already have enough PII to sound legitimate.
Retention policy: the 90-day ceiling that limited blast radius
Trezor’s privacy posture here is unusually concrete for hardware retail. The company says it deletes or anonymizes eShop purchase data after 90 days—the shortest window it judges still covers delivery, returns, refunds, and replacements—and that it negotiated the same deletion rule into fulfillment-partner terms. That is why ShipMonk’s retained set was not “every Trezor buyer since 2013.” Older customers largely aged out of the logistics database before August 8.
The caveat is the partial-exposure cohort of 1,947 people. Trezor’s update admits some of those name/city/email rows may include older orders and that verification with ShipMonk continues. If you received a notification despite believing your order was outside the window, trust the email over your memory of the calendar.
For product and privacy teams elsewhere, the lesson is operational: retention SLAs with 3PLs only help if partners actually purge on schedule and if analytics mirrors (Metabase and similar) do not indefinitely retain extracts. A SOC 2 report does not replace purge evidence.
Communications checklist for affected customers
When the [email protected] notice arrives, save it. Compare any later message’s From domain, Reply-To, and links against that original. Trezor will not ask for your seed phrase to “remediate” ShipMonk. Couriers will not ask for your BIP39 words to release a package. Banks will not need your hardware-wallet backup to “freeze crypto fraud.”
If a caller already knows your order number, name, and street address, that proves data access—not legitimacy. Hang up and contact the institution using a number from a card or official app, not from the suspicious call.
On social media, distrust “I work at Trezor, DM me your ticket.” Support workflows go through official portals. BreachHistory and crypto Twitter threads are secondary; the primary document is the trezor.io blog post titled for this shipping-provider incident.
Comparing logistics breaches in August 2026
The same month, CEVA Logistics’ European warehouse intrusion drove notices to Valve/Steam hardware buyers and multiple Dutch retail brands. Trezor’s ShipMonk/Metabase path is a different vendor and mechanism. Conflating them helps nobody’s IR. What they share is the structural lesson: physical goods force PII into 3PL systems, and those systems are now first-class breach targets.
Simian’s Dutch printing-group supplier breach the same week likewise shows consumer brands absorbing third-party fallout. Hardware wallets simply raise the emotional and financial stakes of the phishing that follows.
What regulators and class counsel will watch
Multi-country exposure (US, UK, EU members, LatAm) implies a patchwork of notification duties. Trezor’s direct email campaign is the consumer-facing piece; ShipMonk’s Metabase-driven notices to its own customers are another. Expect follow-up questions about whether phone and address fields were encrypted at rest, how long Metabase retained query results, and whether purge jobs for 90-day data were audited.
None of that changes the immediate advice for individuals: assume phishing, protect seeds, verify channels.
For journalists and researchers
Primary sources for this story are Trezor’s August 13 blog, ShipMonk customer emails describing the Metabase vector (as reported by BleepingComputer), and Trezor’s X thread matching the user-facing language about seven countries and the 90-day window. Secondary crypto outlets (CryptoPotato, Bitcoin Magazine, BeInCrypto, CoinDesk) largely amplify those facts. Avoid citing unverified forums claiming seed databases or wallet drains tied to this incident without evidence—Trezor’s position is that devices and backups were untouched.
FAQ: Trezor ShipMonk breach
Did hackers steal my Bitcoin? Not via this incident per Trezor—the leak is order PII at a shipper, not device keys. Should I move coins to a new wallet? Only if you already shared a seed with a phisher; otherwise focus on ignoring social engineering. Is ShipMonk the same as CEVA? No—different logistics provider and reported Metabase path. Why seven countries? Those are markets where ShipMonk fulfilled Trezor parcels under the retained-data window. What if I used a work address? Your employer mailroom may see scam packages or calls; brief receiving staff.
People searching “Trezor shipping provider data breach,” “ShipMonk Trezor Metabase,” or “Trezor 13689 customers” should land on the official notice and this BreachHistory record. We will update if Trezor revises the partial-exposure timeframe or if ShipMonk publishes a broader customer census.
Stay patient, stay offline with seeds, and treat every urgent message that name-drops this breach as hostile until proven otherwise through a bookmark you already trust. Hardware wallets exist so that strangers on the internet cannot spend your coins—do not surrender that advantage because a logistics vendor lost a spreadsheet of street addresses. The cryptography held; your operational security still has to. If you teach one household rule after this Trezor ShipMonk disclosure, make it: nobody legitimate will ever need your recovery phrase to “fix” a shipping breach—and anyone who asks is the attack.
Canonical record and sources
Trezor / ShipMonk 2026 on BreachHistory.
Bookmark the official incident URL now so future phishing sites cannot outrank it in your personal habits. Re-read Trezor’s FAQ section when ShipMonk finishes verifying the partial-exposure timeframe, and watch for Anonymous Delivery availability if privacy-conscious ordering matters to you going forward.
Sources: Trezor blog, BleepingComputer, CryptoPotato, Bitcoin Magazine.