Skip to content

News · Security

Trezor’s shipping partner leaked customer details. The device is not the leak.

Names, phones, and addresses came from a logistics company. Recovery phrases did not. Phishing is the part that can still hurt you.

ECGBy EasyCryptoGuides · Editor · Published · 2 min read

A long warehouse aisle lined with tall pallet racks and cardboard boxes
Photo on Unsplash
In this article

On 13 August 2026 Trezor published a notice: ShipMonk, one of the firms that stores and posts its hardware wallets, had unauthorised access to customer order data. Trezor said it learned of that access on Monday 10 August. The blast radius is recent parcels — orders received in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between 10 May and 8 August 2026 — because Trezor’s policy is that fulfilment partners delete or anonymise that data after 90 days.

The company counted 11,742 customers with full exposure (name, email, phone, shipping address) and 1,947 with a thinner set (name, city, email). Trezor later said some of those partial records might include older orders. It emailed the people it believes are affected. If you did not get that mail from Trezor’s notice address, the firm says you are not in this dump. Amazon orders, it added, go through a different partner.

What happened

This is a vendor story. ShipMonk holds what a courier needs: who you are and where to leave the box. That is enough for a convincing fake “your Trezor needs a firmware check” email, phone call, or letter. It is not enough to move coins. Trezor says its own systems, products, and recovery backups were not touched. A hardware wallet does not become unsafe because a warehouse database did.

How ShipMonk was entered is their investigation. Public reporting has pointed at a business-intelligence tool in the logistics stack. You do not need that subplot to act. You need the list of what left: contact details, not keys.

Why it matters

Self-custody is often sold as “nobody has your data”. Buying a device still means a shop, a payment, and a parcel. Those are companies. In December 2020 a Ledger shop dump put buyer addresses on a forum. In January 2024 Trezor’s own third-party support portal was accessed. The lesson repeats: the cold wallet can be fine while the invoice is not.

The harm to watch is phishing that already knows your name, your street, and that you recently bought a signer. Nobody legitimate needs your recovery phrase to “validate firmware”, “restore after a breach”, or “unlock a shipment”. If a message hurries you toward those words, it is not support. For the mechanism of keys versus apps, see how crypto wallets actually work; for habits after a scare, see a practical checklist for keeping crypto safer.

What you should actually do

If you were emailed by Trezor, treat other channels as hostile for a while: new domains, QR codes, attachments, phone numbers that call you first. Do not type a backup into a website. Do not photograph it for a “ticket”. A parcel to a PO box or a locker would have shrunk this particular leak; it would not have deleted the need for a name on a label.

What happens next

Forensics at the logistics firm, and a rise in tailored scam copy. Trezor says it has not confirmed the data being sold. Assume someone will try anyway. We will not turn a shipping incident into a reason to abandon hardware wallets — or into a reason to trust every box that arrives with a logo on it.

Not a review of Trezor or ShipMonk. Not an instruction to buy, sell, or move coins tonight.

Topics

This article is for information only and is not financial advice. Cryptoassets are volatile and you can lose money. See our disclaimer.

Comments

Keep it civil. First comments wait for an editor. This is not financial advice, and we remove spam or “DM me for signals” posts.

No comments yet. Be the first — keep it civil, and skip the tips.

Sign in to comment. Reading never requires an account.

Back to top

Continue reading

Stay a little clearer on crypto

Guides, reviews, and the news that actually matters. Unsubscribe anytime.

By subscribing you agree to our privacy policy.

More news

View all