Trezor has disclosed that personal data belonging to approximately 13,689 of its customers was exposed through a breach at ShipMonk, one of its shipping providers. In its own statement published on 13 August 2026, the hardware wallet maker said it learned of the unauthorised access on Monday, 10 August 2026, and that the exposure relates to orders shipped between 10 May and 8 August 2026.
The company broke the exposure into two groups: 11,742 customers had full exposure — name, email, phone number and shipping address — while a further 1,947 had partial exposure (name, city and email). Affected customers are located in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Crucially, Trezor was emphatic that the breach did not reach the product itself. “Our systems were not compromised, and your Trezor device is secure,” the company wrote, adding that “No Trezor system, product, or service was affected.” No wallet backups, private keys, recovery seeds or funds were exposed; the incident is confined to customer and shipping data held by the third-party logistics partner.
That distinction matters, but it does not make the exposure harmless. With names, email addresses, phone numbers, and, for most of those affected, home shipping addresses now in the wrong hands, the immediate danger is targeted phishing and social engineering. And because the physical addresses of known hardware wallet owners have leaked, there is a heightened personal security dimension, too.
Trezor’s guidance to users: “Never enter your wallet backup on a website or share it with anyone,” “Be suspicious of any communication that prompts immediate action or asks for personal information,” and “Always cross-reference email and web content with official Trezor communications.”
In response, Trezor pointed to an “Anonymous Delivery” option it says is coming soon, targeting EU availability by September 2026 and the US by the end of 2026, intended to keep customer identity out of the shipping chain in future.
A different failure mode from Coldcard
For readers of RegTech.com, the episode rhymes with but is materially different from the Coldcard firmware incident we covered earlier this month. There, the weakness sat in the device itself: a firmware randomiser flaw that degraded key generation and put funds directly at risk. Here, the device is sound; it is the supply chain around it, a third-party fulfilment provider, that failed.
Taken together, the two cases point to a broader truth for the hardware wallet sector: protecting self-custody customers is no longer only about the security of the device, but also about every vendor that touches a customer’s identity, order, and delivery data.
For compliance and security teams, that puts third-party/vendor risk management and breach notification obligations squarely back in focus.
