Search

Trezor Suffers Data Breach Affecting Nearly 14,000 Customers

Trezor Discloses Data Breach Affecting Nearly 14,000 Customers

The incident is the first in Trezor’s 13-year history to expose customer phone numbers and home addresses, and it lands in the middle of Bitcoin’s worst month for infrastructure security in recent memory.

Prague-based hardware wallet maker Trezor disclosed on Thursday that ShipMonk, one of its shipping and logistics providers, was hacked, exposing the personal data of nearly 14,000 customers. The breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026.

“On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data,” Trezor said in a statement. “The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).

ShipMonk told affected customers in breach notification emails that attackers exploited a vulnerability in the third-party analytics platform Metabase.

“On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase’s software to access data related to your account and your customers,” ShipMonk said. “Based on the vendor’s representations, we understand that the vendor has since patched the vulnerability and invalidated all active sessions.”

Metabase is a widely used business intelligence tool that companies connect to their databases for internal reporting. A SQL injection flaw—a type of attack where malicious code is inserted into a database query to gain unauthorized access—was used to compromise customer instances.

According to the Czech company, the breach was limited by the firm’s 90-day data retention policy, which requires fulfillment partners to delete or anonymize order-related customer information after three months. As a result, older order data was no longer in ShipMonk’s systems at the time of the breach. Trezor says it negotiated those same deletion terms with its fulfillment partners, meaning the policy held across the supply chain, not just internally.

Trezor told CoinDesk it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and is unaware of any scam or hack attempt linked to the incident so far. Customers who purchased through Amazon are not affected, as those orders are fulfilled by a separate partner.

A recurring problem for the hardware wallet industry

While Trezor stressed a point that its hardware wallets and internal systems were not compromised, the data in ShipMonk’s systems—names, phone numbers, email addresses, and home delivery addresses—is a particularly attractive target for attackers.

“Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts,” the company said. “NEVER enter your wallet backup on a website or share it with anyone, and only check for updates on official Trezor channels.”

The 2020 precedent at rival Ledger illustrates how far the risk can run. After roughly 272,000 Ledger customers had names, addresses, and phone numbers published, some began receiving ransom demands threatening violence. Analyses of these trends have linked a surge in violent attacks on crypto executives and high-net-worth individuals to a series of PII-focused breaches at companies including Ledger, Kroll, and Coinbase.

In that 2020 incident, criminals demanded between $700 and $1,000 in Bitcoin, warning that refusal could lead to doxxing or physical harm. The data was later dumped publicly online, and the threat environment it created did not age out—years later, researchers were still finding that threat actors were repackaging and re-selling enriched versions of the original dataset.

One particularly stark case: the January 2025 kidnapping of Ledger co-founder David Balland and his partner, during which attackers severed Balland’s finger while demanding ransom.

CertiK verified 52 physical attacks on crypto holders worldwide in just the first half of 2026. Someone might say that Trezor’s breach is smaller in scale than Ledger’s 2020 incident, and the data has not been published, but the nature of the information—home shipping addresses tied to known hardware wallet buyers—means the risk profile is elevated regardless.

Trezor’s response: anonymous delivery on the way

Trezor says it is working toward an Anonymous Delivery option that would allow customers to purchase hardware wallets without linking the order to their home address or real-world identity. The planned features include a dedicated checkout with a nickname or label ID, automated parcel locker pickup, and unbranded packaging with a generic sender label. The carrier would contact the buyer only via email or SMS with a pickup PIN.

The company is targeting EU availability by September 2026 and US availability by the end of the year.

The direction is the right one, although one may reasonably ask why it took a breach of this kind to accelerate work that privacy-conscious users have been requesting for years. Locker delivery and privacy-preserving checkout are not technically complex features, and the fact that they are now described as a “top priority” suggests the urgency was not always there.

The worst month in recent Bitcoin history

The Trezor breach does not land in isolation. August 2026 has been an extraordinarily damaging period for Bitcoin infrastructure.

The month follows the fallout from the Coldcard seed generation vulnerability, which has drained roughly $114 million in BTC since July 30, hitting more than 5,200 addresses, with some victims reporting the loss of life savings.

On August 3, the swap bridge Boltz, which connects Bitcoin’s main chain to the Lightning Network and the Liquid sidechain, suspended operations indefinitely after AI-driven attacks outpaced its small development team.

“Attackers now iterate faster than a team our size can find and patch,” the company said.

Three wallets—Aqua, Bull Bitcoin, and Zeus—lost access to Boltz-powered swap functionality within hours of the halt.

Zeus, a non-custodial Bitcoin Lightning wallet, then pulled its own infrastructure offline on August 5 after detecting a separate cyberattack, becoming the third Lightning Network service provider to suspend operations in roughly 72 hours.

The BTCPay Server exploit was the third significant security failure to hit Bitcoin’s surrounding infrastructure in under two weeks. Attackers closed Lightning channels and swept funds held through those channels. Hardware wallet maker Foundation and the Bitcoin zine Citadel21 both had Lightning nodes drained — some hours before BTCPay’s own public warning went out. The bug was found only because a developer, Craig Raw of Sparrow Wallet, lost funds and analyzed the logs.

None of these incidents affected Bitcoin’s consensus protocol or cryptography. But taken together, they represent a sustained assault on the infrastructure that ordinary users and merchants depend on to hold, move, and spend bitcoin, raise uncomfortable questions about the security standards of the broader ecosystem.

The Trezor breach is, in one sense, the least severe of these events: no funds were lost, and the company’s response has been prompt and transparent. But it adds to a month in which Bitcoin’s surrounding stack has been tested relentlessly, and found wanting more than once.