Crypto hardware wallet maker Trezor has disclosed that a shipping provider has experienced a data breach, exposing the private data of over 13,000 customers. The incident comes barely two weeks after the Coldcard hack incident that led to over 100 million in Bitcoin ($BTC), further dampening confidence in the hardware wallet industry.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
Trezor data breach puts thousands of $BTC at risk
According to an official announcement, the data breach stems from ShipMonk, one of Trezor’s shipping partners. Per the statement, bad actors gained unauthorized access to ShipMonk’s systems containing the personal data of over 13,000 customers who ordered Trezor devices between May 10 and August 8, 2026.
The breach affected 11,742 customers, with bad actors accessing their full names, phone numbers, email addresses, and shipping addresses. Furthermore, an additional 1,947 customers had their information exposed partially, with hackers only being able to access their names, email addresses, and cities.
An early post-mortem indicated that the data breach affected new customers in the US, UK, Sweden, Brazil, Colombia, Italy, and Portugal. However, Trezor says its strict 90-day data storage policy limited the scale of the breach. The company also stated:
“This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected.”
Trezor warned users that while its systems were not compromised, affected customers are vulnerable to sophisticated phishing attempts. The hardware wallet provider warned that bad actors can use their personal details to send fake emails and make bogus phone calls, impersonating banks and other cryptocurrency exchanges.
Apart from phishing attempts, pundits are predicting a surge in physical attacks following the release of shipping addresses. In 2026, crypto “wrench” attacks have led to the loss of $30 million, with bad actors kidnapping Bitcoin holders and demanding ransoms in digital assets.
Trezor races to protect users with anonymous delivery option
In its statement on X, Trezor revealed plans to launch an Anonymous Delivery option for customers to prevent a repeat of the incident. The company tagged the feature “a top priority,” eyeing a rollout by September for the EU and an end-of-the-year launch for the US.
While exact details are sparse, the feature will allow users to order hardware wallets without linking the purchase to home addresses or real-world identity. Trezor’s scoop hinted at the use of dedicated checkout, nicknames, unbranded packaging, and the ability to select an automated parcel locker for pickup.
In the meantime, the company urged users to use an anonymous email address that is not linked to their real identity. Trezor added that users should consider paying for their hardware wallets with digital assets rather than credit cards as an extra layer of protection.
The incident comes as trust in hardware wallets has dipped to an all-time low. The sector is yet to recover from the jarring Coldcard hack at the tail end of July, with on-chain sleuth ZachXBT branding all hardware wallets as “trash.”
coincodex.com