On 13 August 2026 Trezor disclosed that 13,689 of its customers were affected by a breach at ShipMonk, the logistics provider that ships its hardware wallets. For 11,742 people the exposure covers name, email address, phone number and shipping address; for another 1,947 it is limited to name, city and email. Orders placed between 10 May and 8 August 2026 are in scope, across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
The chain runs four organisations deep. Metabase, an analytics platform, told ShipMonk on 6 August that an unauthorised party had exploited a flaw in its software to reach data tied to ShipMonk’s account. ShipMonk told Trezor on 10 August. Trezor told its customers on the 13th. The flaw is the Metabase zero-day this database filed at 26-0811, which had already reached five companies before disclosure — this file records its arrival at the people standing at the end of the chain.
The Device Never Mattered
Trezor states its own systems were untouched and no customer device was compromised. Both statements are plausible and neither is the point. A hardware wallet exists to keep signing keys off any network, and the protection worked exactly as designed.
What leaked is the customer list — and a hardware wallet customer list is a directory of people known to hold bearer assets, annotated with where they live. The corpus recorded at 25-0530 what that combination is worth: Coinbase put a nine-figure estimate on remediation after its support data reached attackers, because each record is a qualified lead for a fraud with an irreversible settlement mechanism.
A Shipping Label Is A Security Boundary
Nobody in this chain mishandled the data by the standards of their own business. A fulfilment provider needs names and addresses to ship parcels; an analytics platform needs access to the data it analyses. Each link was ordinary.
The composition is what failed. A customer who bought a security device from a security company was exposed by an analytics tool used by a warehouse they had never heard of. No purchase decision available to them touched any link in that chain, and the notification letter they received is from the one company in it they chose.
What The Letter Can And Cannot Fix
Trezor’s advice to affected customers is to expect convincing phishing that quotes real order details, and never to enter a recovery seed anywhere a message asks. That is the right advice, and it addresses the smaller half of the exposure. An address does not expire and cannot be rotated. For a subset of holders, the risk that follows a published address is physical, and no mailing-list remedy speaks to it.
Compiled from Trezor’s customer notice and contemporaneous reporting, listed below. The per-tier counts and order window are the company’s. The identification of the Metabase flaw as the route is as stated by ShipMonk via Trezor’s account and reporting of it. Graded high. Corrections: corrections@forensicpost.com.