Trezor discloses data breach affecting nearly 14,000 customers
I’ll pull the BleepingComputer report and official Trezor details first so the paragraphs stay on verified names and numbers.The request is body copy only,…
By Dillip Chowdary • Aug 14, 2026 • Source: BleepingComputer
What happened
I’ll pull the BleepingComputer report and official Trezor details first so the paragraphs stay on verified names and numbers.The request is body copy only, so I’m verifying the BleepingComputer piece and Trezor’s own notice before writing.Trezor, the hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers after ShipMonk, its shipping and logistics provider, was hacked. In a Thursday, August 13, 2026 blog post, Trezor said ShipMonk informed it on Monday, August 10, 2026 of unauthorized access to systems containing customer data. The incident affects 11,742 customers with full exposure of name, email, phone number, and shipping address, and 1,947 customers with partial exposure of name, city, and email, or approximately 13,689 people. The exposed set is customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026. Trezor said its systems were not compromised, Trezor devices remain secure, and private keys and wallet backups were not part of the leak.
ShipMonk stores Trezor products and ships orders in those markets. To hand a parcel to a carrier it holds name, email address, order number, phone number, and shipping address; carriers require a phone number. Trezor requires fulfillment partners to delete or anonymize order data 90 days after delivery, a window it says is the shortest that still covers delivery, returns, refunds, and replacements. That is why Trezor says only recent orders should have been in ShipMonk systems, though it later said the 1,947 partial-exposure records may include older orders and is verifying that with ShipMonk. Notification emails reviewed by BleepingComputer show ShipMonk telling customers that on August 6, 2026 Metabase informed ShipMonk an unauthorized party exploited a vulnerability in Metabase software to access data related to ShipMonk's account and customers. BleepingComputer has reported the same campaign as a critical SQL injection zero-day used to breach customer Metabase instances, gain administrator access, and steal data. ShipMonk said Metabase patched the vulnerability and invalidated active sessions, and that it opened a technical investigation with outside experts.
The technical detail

The engineering lesson is about the fulfillment plane, not the secure element. A hardware wallet is built so the seed and private keys never leave the device; that isolation held. What failed is the order pipeline that has to exist because Trezor sells a physical object. Names, street addresses, emails, and phone numbers of people who just bought a vault are a high-value phishing list, and Trezor warned that scammers can send fake emails, make fake phone calls, send fraudulent letters, or impersonate banks, crypto exchanges, or Trezor itself. Trezor said this is the first time since it was founded in 2013 that a breach exposed customer phone numbers and shipping addresses. Builders who ship security hardware inherit carrier-mandated personal data, warehouse tenants, and whatever analytics tool the warehouse pointed at the order table. A contractual 90-day deletion clause only bounds the blast radius if the partner actually deleted, which is now an open question for the partial-exposure cohort.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters for builders
The same pattern showed up around other brands in the same window. Valve notified Steam hardware customers in Europe that hackers stole data after compromising CEVA Logistics, Valve's shipping partner. Framework and Tally also notified customers after their Metabase instances were hijacked in the same class of attack. BleepingComputer later learned ShipMonk received extortion emails from the ShinyHunters extortion gang. Hardware-wallet vendors compete on device integrity and self-custody; those claims are not what this incident tests. It tests whether buying the device creates a durable list of owners at a third-party logistics firm that also runs analytics software with a path to production order data. One warehouse plus one business-intelligence product is enough to turn a SQL injection into a multi-country customer dump, then an extortion demand aimed at the logistics operator rather than the brand.
Market and competitive context
Trezor says every affected customer has been emailed, and that anyone who did not receive a message from its notification address is not in the exposed set. Treat unexpected emails, calls, and letters that demand immediate action or a recovery seed as hostile, and never enter a wallet backup on a website or share it. For later orders Trezor lists an anonymous email, paying with crypto or a disposable card, a P.O. Box where possible, and an Anonymous Delivery option it aims to offer in the European Union by September 2026 and in the United States by the end of 2026, using locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. Watch for a complete account from ShipMonk and Metabase of which fields were read, whether the 1,947 partial records include older orders, and whether ShinyHunters publishes or auctions the file.
What to watch next
Trezor already had a related third-party failure in January 2024, when attackers reached its support ticketing portal and 66,000 users who had contacted Trezor Support since December 2021 may have had names, usernames, and email addresses exposed. After that breach Trezor confirmed the stolen contact data was used in phishing that tried to collect the 24-word recovery seeds issued at wallet setup. The ShipMonk set is smaller but denser: most of the 11,742 fully exposed buyers now have phone numbers and street addresses next to email. Trezor did not describe how ShipMonk's Metabase instance was reachable, and it is not public whether order numbers or other fulfillment fields beyond the named personal data were copied, or how many other ShipMonk merchants sit in the same extract.
Advertisement
🔎 More interesting news
- Google announces Gemini 3.7 Flash just three weeks after previous release
- SpaceXAI debuts Grok 4.6, overtaking Kimi K3's performance and matching GPT-5.6 Sol for…
- Writer introduces new AI model and upgraded harness to contain token costs
- ChatGPT for Mac adds opt-in Computer History feature, replacing Chronicle
- Today's full Tech Pulse briefing →