On 13 August 2026, hardware wallet maker Trezor announced that a data breach at ShipMonk, its external logistics partner, had exposed order data for 13,689 customers. For 11,742 of them, names, email addresses, phone numbers and shipping addresses were affected; for 1,947 others, only names, cities and email addresses. Those concerned received an order in the 90 days before 8 August 2026, in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor states that its own systems and its devices were not compromised, and warns against fake emails, fraudulent calls and people impersonating banks or exchanges.
A hardware wallet is a small device that keeps private keys away from any connected computer. The recovery phrase, the 12 or 24 words that restore a wallet, never leaves the device and is known only to its owner. A leak of shipping data therefore gives no access to funds. What it does reveal is sensitive in another way: who owns a hardware wallet, along with their name, phone number and address. That is exactly the raw material of phishing campaigns. In 2020, a comparable leak at rival Ledger exposed customer contact details and fed years of fake emails and threatening messages.
For those affected, the risk is not technical but human. The most common attempts take the form of an email announcing a security problem and inviting the recipient to enter their recovery phrase on a site imitating the manufacturer's, a call pretending to be support, or an unsolicited replacement device in the post. Two rules hold without exception: no manufacturer, no support desk and no exchange ever asks for a recovery phrase, and that phrase is only ever entered on the device itself. A wallet received without having been ordered must never be used.
What to watch: official statements from Trezor and ShipMonk on the exact scope of the breach, the individual notification of affected customers, and the shelf life of such lists, which often circulate for years after an incident. Anyone can check whether they fall inside the window, namely an order received in the 90 days before 8 August 2026, and stay particularly wary of any message mentioning their wallet in the coming months.