← Back to Learn

The Trezor Breach: Protect Your Address, Not Just Your Keys

On August 10, 2026, Trezor learned that one of its shipping providers had been breached. No Bitcoin moved. No keys were touched. What leaked was a list of people who had just bought a hardware wallet, along with where to find them.

What actually leaked

The breach happened at ShipMonk, the fulfilment company that packs and posts Trezor orders, not at Trezor itself. ShipMonk has said attackers got in through a flaw in a third-party analytics tool it used. Order data went with them.

The numbers, in Trezor's own words

“The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email).”

That's roughly 13,700 people in total, covering orders received between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

Trezor has been clear about the other half of it: its systems, hardware wallets, private keys, and wallet backups were not affected. Nobody can spend your Bitcoin with a shipping label. If you own a Trezor, you do not need to move your funds because of this, and you do not need to generate a new seed phrase.

Why a delivery list is worth stealing

A list of hardware wallet buyers is not like a leaked list of, say, shoe buyers. It answers three questions at once for anyone who reads it: this person probably owns Bitcoin, this person holds it themselves, and this is the address it's held at. That combination is unusually specific, and it's the reason these lists get sold rather than shrugged off.

What follows a leak like this is usually paperwork, not drama. Phishing emails that quote your real order. Texts from “support” that already know your name. Calls that open with your address so you'll assume the caller is legitimate. The details make the approach believable, and believability is the whole product.

We have a long, well-documented example of how far it can run. In 2020, Ledger's e-commerce and marketing database was breached, exposing around a million email addresses and roughly 272,000 records that included full names, phone numbers, and home addresses. The file was dumped publicly that December. What came afterwards went on for years: phishing waves, extortion emails demanding a few hundred dollars in Bitcoin, and, in 2021, tampered “replacement” devices mailed to addresses from the dump, with official-looking letters telling people to enter their recovery words into the new hardware. Ledger's customers were leaked again in January 2026, this time through Global-e, a third-party e-commerce partner, with names and contact details exposed.

Notice where the failures keep happening

Three incidents, two companies, six years apart, and not one of them was a broken wallet. The devices did their job every time. The leaks came from the ordinary business around the device: an online store, a marketing database, an analytics tool, a warehouse that packs boxes.

That layer is not built to Bitcoin security standards, and it never will be. It involves many companies you didn't choose and can't inspect, each holding a copy of your details because they needed them for a week to get a parcel to you. Any one of them can be the weak link, and you find out which one only afterwards.

So the practical question isn't which vendor to trust. It's what you hand over in the first place. Data that was never collected can't leak.

If you ordered a wallet recently

Nothing here is urgent, and nothing here involves touching your Bitcoin. It's a handful of habits worth having anyway:

  1. Assume any message about the breach is fake until you check. Open trezor.io yourself, typed into the address bar. Don't click through from an email, no matter how correct its details are.
  2. Never enter your recovery words anywhere. Not a website, not a form, not a support chat, not an app that asks you to “verify” or “migrate” your wallet. There is no legitimate reason to type them into anything but the device itself.
  3. Treat unexpected packages as suspect. A hardware wallet you didn't order, a “free replacement,” a firmware stick in the post. Bin it, or contact the vendor through their own site first.
  4. Lock down the phone number that leaked. Call your mobile provider and add a port-out PIN, so someone can't move your number to their own SIM and walk through your text-message logins.
  5. Move any accounts still using SMS codes to an authenticator app. That's covered step by step in digital security hardening.
  6. Don't announce what you hold. Not online, not at dinner. A leaked address is one data point; your own confirmation is the other one.

If you find yourself being pushed to act quickly, that pressure is the tell. Real security news gives you time to slow down and check.

The lesson: buy in person, or ship somewhere else

The most reliable fix for a leaked shipping address is to never create one.

Buy at a Bitcoin conference or meetup. The major hardware vendors sell from their own booths at Bitcoin events, and plenty of local meetups have someone who can point you at the next one nearby. You hand over cash or pay in Bitcoin, you walk away with the device, and no database anywhere gains a row with your name and your front door in it. It's the same purchase, minus the paper trail.

If you do order online, don't ship it home. A P.O. box, a parcel locker, a pickup point, a workplace, or a friend's address all break the link between “owns a hardware wallet” and “lives here.” Pair it with an email alias you use only for that order, and pay in Bitcoin where the vendor accepts it. Trezor has said it plans to add an anonymous delivery option in the EU from September 2026, which is a welcome direction, though it's worth remembering the shipping company still has to know where the box is going.

Buy direct either way. In person from the vendor, or from the vendor's own website. Not a marketplace reseller, not a listing with fast shipping and a good price. Saving your address is not worth introducing the possibility that somebody opened the box first. If you're unsure whether a shop or app is really the company it claims to be, here's how to check.

Keeping this in proportion

Roughly 13,700 people had order details exposed. For nearly all of them, this will amount to some well-crafted spam and a reason to be careful for a while. The overwhelmingly likely outcome is nothing at all.

It's also not a reason to skip the hardware wallet. Leaving Bitcoin on an exchange hands over the coins themselves, not just the delivery address, and exchanges hold far more of your personal information than a warehouse does. The device is still the right move. This is a note about how to buy it, not whether to.

The wider habit is the useful part: your Bitcoin security isn't only the seed phrase in the safe. It's also which forms you filled in, which companies hold your address, and how many lists connect your name to the fact that you hold anything at all. Those are decisions you make at checkout, and you only get to make them once per order.

Common questions

Was anyone's Bitcoin stolen in this?

No. This was a shipping and order-data leak. Trezor's devices, its firmware, private keys, and wallet backups were not involved, and no funds moved because of it. What leaked was the paperwork around the purchase, not anything that can spend your coins.

How do I know if I was affected?

Trezor said the exposure covers orders received between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, and that it is contacting affected customers directly. Check trezor.io yourself rather than trusting an email that claims to be the notification.

I got an email about the breach asking me to verify my wallet. Is it real?

Treat it as a scam. A leaked buyer list is exactly what makes convincing fake notices possible, because the sender already knows your name, your order, and your address. No wallet company will ever ask you to enter your recovery words on a website, in an app, or in a reply.

Is it safer to buy a hardware wallet from Amazon or eBay instead?

No. Buying from a marketplace reseller trades a privacy risk for a much worse one: you no longer know that the device came from the manufacturer untouched. Buy direct from the vendor, or in person from the vendor at an event. The fix for the address problem is where it ships, not who you buy from.

Does a P.O. box or a conference purchase make me anonymous?

No, and it isn't meant to. It keeps your home address off one more list. Your identity is still known to whoever you buy Bitcoin from, and that's a separate question. This is about limiting how many databases hold the line that says you own a hardware wallet and here is where you sleep.