The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Trezor Data Breach: Am I Affected and What Should I Do Now?

Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.

Open shipping box on a dark doorstep, blank white shipping labels beside it and a Bitcoin coin standing upright
15 min read
Share:

Whether you are affected by the Trezor data breach comes down to a single question: is there an email from help@trezor.io about the incident in your inbox? Trezor says it notifies every affected person individually. Anyone who has not received that message is, according to the manufacturer, not in the exposed records.

On September 4, 2026, Trezor widened the incident for the second time. Around 67,000 further customers in the United States were added to the 13,689 reported in August, bringing the total to just over 80,000 people. Exposed were the full name, delivery address, phone number, email address and order number. Not exposed were the contents of the parcels, the devices themselves, private keys or wallet backups.

This article answers the question behind the headline that nobody has answered in German so far: whether German customers appear in this second wave at all, how you check that, and what an open address book means for someone who holds crypto assets in self-custody.

Am I affected by the Trezor data breach? The check takes two minutes

Trezor has taken the same route for both waves: those affected are informed directly by email, sent from help@trezor.io. The sentence appears verbatim in the blog post on the incident, and it works in both directions. No mail from that address means, in the manufacturer's account, that you are not affected.

The notification itself distinguishes two levels. With full exposure, the name, email address, phone number and delivery address are affected. With partial exposure, it is only the name, city and email address, with the street address missing. Which of the two applies to you is stated in the mail. That is not a formality: an exposed street address weighs considerably more heavily than an exposed city.

And if you are not sure about the mail

This is exactly where the real risk begins. A data breach that is reported publicly is an invitation to fraudsters, because thousands of people are expecting a warning email right now. So check the sender address character by character, open no attachments and follow no link from the mail. If you want to know whether a message is genuine, call up the Trezor site yourself through your browser's address bar and look for the blog post on the incident there. The route via the address bar is the only one an attacker cannot fake.

What was exposed at ShipMonk and what was not

ShipMonk is a fulfilment provider, a company that stores a manufacturer's goods, packs orders and ships them to customers. For that job such a provider needs precisely the data that has now leaked: name, delivery address, phone number for the courier, email address and order number. Trezor describes ShipMonk as one of its shipping partners for the United States, the United Kingdom and other countries.

On August 10, 2026, ShipMonk reported unauthorised access to systems holding customer data to the manufacturer. Trezor made the incident public on August 13. What was expressly not affected is the more important part of the disclosure: Trezor's own systems were not compromised, according to the company, the devices are safe, and private keys and wallet backups are untouched. The contents of the parcels do not appear in the data either. An attacker therefore knows that an order went to a particular address, but not which device was in it or how much sits on it today.

Why this still concerns you as a self-custodian

A hardware wallet is a device that keeps your private keys permanently offline and signs transactions only after confirmation on the device itself. That makes it the standard tool of self-custody, and it carries one unavoidable side effect: it remains a physical product. Anyone who buys one has to have it delivered, and in doing so leaves a name, an address and a phone number with at least one intermediary. That is exactly the trail exposed here. If you are currently weighing up which device and which purchase route suits you, the hardware wallet comparison helps with the choice. Since this incident, the data trail left by an order belongs among the criteria that go into that decision.

Open metal letterbox at dusk holding a blank white envelope, with a Bitcoin coin standing on its edge in front of it
Once a home address and phone number are exposed, the attack moves from the inbox to the letterbox.

Why Germany appears on neither list of affected customers

Trezor names the countries affected in both waves, and the result is unambiguous for German readers. The first wave covered orders from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, delivered between May 10 and August 8, 2026. The second wave affects customers in the United States exclusively, according to the manufacturer. Germany appears in neither list.

That is a piece of information with a limit, and the limit belongs with it. What counts is the delivery address, not the place of residence or nationality. Anyone who had a device sent to an address in one of the countries named can be affected even if they live in Germany. And the country list does not replace the check: what matters remains the notification from help@trezor.io.

The second wave hits an entirely different group of buyers

The real finding in this update is not the number but the period. The first wave concerned fresh orders from the spring and summer of 2026. The roughly 67,000 new records come from an earlier collaboration between November 2019 and August 2021. These are people who ordered a device four to seven years ago and may never have bought there again since.

For this group the situation reverses. Anyone who read the first report in August 2026 and found that their last order was years back had good reason to consider themselves unaffected. Since September 4 that no longer holds. Our report on the first wave of the ShipMonk data breach gives the figure of 13,689 affected customers that applied at the time. That number has been overtaken by the update; the sequence of events and the mechanics described there hold unchanged.

Why this is more than a revised figure: the second wave consists throughout of full exposures, according to Trezor, so name, email, phone number, delivery address and order number as one package. And it hits orders from a time when crypto assets were worth considerably less than they are today. Someone who bought in 2020 and held is statistically sitting on a larger balance than someone who came in during 2026. Any attacker makes that connection unaided.

Deletion confirmed in writing, data present anyway

Trezor works, by its own account, with a retention period of 90 days: order data is to be deleted or anonymised 90 days after delivery, and the company says it agreed the same condition with its shipping partners. In the report of August 13 that very period was cited as the reason the damage was limited.

The update of September 4 pulls the ground out from under that argument. Trezor writes that it repeatedly requested, and received, written confirmation of deletion throughout the collaboration, and that it is deeply disappointed the data was not deleted in the provider's systems despite that confirmation. This account comes from the manufacturer; a statement from the provider on the matter is not available to us.

What you take from this for every other provider

The point generalises, which makes it the practically most valuable one in the whole affair: a contractual deletion period is a promise, not a guarantee. The contract describes what a provider is supposed to do, and says nothing about what is actually still sitting in its databases. You cannot check that from the outside. What you can control is the volume of data you hand over in the first place, and that is what the later part of this article is about.

Why an address leak is not a crypto loss

This distinction is the reason you do not need to move any coins after this report. An attacker who knows your name, your address and your phone number has no access whatsoever to your holdings. Access hangs solely on the wallet backup, the sequence of words your device displayed during setup and from which all private keys can be restored. That word sequence was never held by the shipping provider and is not part of the leak.

Anyone holding Bitcoin or other crypto assets on their own device therefore has no technical reason to swap the device or move holdings after this incident. A wallet whose backup was never recorded digitally and never typed in anywhere stays safe even if the delivery address is public. Only one thing has changed: the probability of being approached in a targeted way.

Steel document shredder overflowing with paper strips, an intact stack of paper in the shadow behind it and a Bitcoin coin in front
Contractually destroyed, actually still there: the old order data should have been deleted long ago.

How to spot phishing after a data breach: the signs that count

Phishing describes the attempt to get you to hand over access credentials or keys through a faked message. After an address leak it becomes precision work: someone who knows your name, address, phone number and order number no longer writes a mass mail but composes a message containing genuine personal details, which is why it reads as credible. Trezor points explicitly to this heightened risk in its own blog post and names faked emails, fraudulent calls and letters.

How you recognise such a message:

  • Urgency. Any message demanding immediate action because something is supposedly blocked, compromised or lost belongs on the test bench. Time pressure is the tool used to prevent checking.
  • A request for recovery data. No reputable manufacturer ever asks for your wallet backup, your word sequence or your private key, not by mail, not on the phone and not on a website.
  • Personal details as a trust anchor. After this leak, an address and an order number are no longer proof of authenticity but an indication that someone is working with leaked data.
  • The link goes somewhere other than it promises. Hover over the link without clicking and read the actual destination. On a phone, a long press rather than a tap does the job.
  • A device arrives unrequested. Anyone who receives a supposedly free or replacement device by post after a leak should not set it up. Tampered devices carrying a ready-made backup are a known line of attack.
  • The call comes from support. Phone numbers are part of the leak. A call back on a number you looked up yourself on the manufacturer's site settles any doubt.

How concrete this can get is shown by the case we described in our article on phishing letters sent to wallet owners: there the attack reached its targets as a printed letter carrying the appearance of an official demand. An exposed home address is what makes that route possible in the first place.

Wallet backup: the one rule every attack fails against

The wallet backup is the recovery sequence of usually twelve or twenty-four words with which your entire wallet can be rebuilt on any other device. Whoever has it has the coins. Hence one rule that holds without exception: these words are never entered on a website, never photographed, never stored in a cloud and never told to anyone, support staff included.

This single rule neutralises practically every attack that follows from an address leak. An attacker can write to you, call you, impress you with your order number and show you a perfectly rebuilt page. As long as the word sequence does not leave your device, the attack has no effect. While you are at it, check where your backup physically sits and whether it would survive water damage or a house fire there.

An exposed home address: what the physical risk means in practice

Alongside phishing, Trezor explicitly names possible risks to the physical safety of those affected in its updated report, and trade media have picked the point up. It is the sober consequence of a data combination: a list of home addresses behind which someone holding crypto assets very probably stands is a different thing from a furniture retailer's customer address list.

In practice that means restraint above all. Anyone who talks publicly about their own holdings, shows them on social networks or appears under their real name in the relevant forums links the leaked address to an order of magnitude. That link is the actual risk factor, and it is the only variable in the equation you still control yourself. Where your backup sits is likewise nobody's business, and a location outside the home has a second advantage here beyond fire protection.

How to order a hardware wallet with a smaller data trail

Trezor itself lists several ways to give away less about yourself when buying. None is restricted to one manufacturer; all of them work with any mail-order retailer:

  1. A dedicated email address for orders that does not carry your name and is linked to no other account.
  2. Payment in cryptocurrency where the retailer offers it, otherwise a virtual single-use card instead of your main credit card.
  3. A pickup address instead of your home address. Trezor names the PO box; in Germany a parcel locker or branch delivery is also an option. Collection usually requires ID, and the courier stores that data in turn.
  4. Buying from the manufacturer rather than through marketplaces. That does not reduce the volume of data, but it does reduce the number of places holding it, and it rules out tampered second-hand devices.

The rest is a trade-off. Each of these measures costs convenience, and none of them makes you invisible. Anyone who wants to avoid the data aspect entirely arrives at a different form of custody: a software wallet is an application on a phone or a computer that stores the keys locally. Such an application is downloaded rather than delivered, so it leaves no delivery address, but it offers less protection against malware on the machine. Which application does what is set out in the software wallet comparison; for larger holdings the combination of both remains the usual route.

What Anonymous Delivery is and when Trezor plans to offer it in Europe

In the same blog post Trezor announces a shipping option called Anonymous Delivery: a separate ordering process with collection at a pickup point, neutral packaging, generic sender details and automatic deletion of the shipping identifiers after delivery. For the European Union the company gives September 2026 as its target, and the end of the year for the United States.

Two qualifications belong with that. First, this is a manufacturer's announcement and not an available product; whether the date holds cannot be checked today. Second, the option solves the underlying problem only in part: even with neutral packaging a courier needs a destination address, and deletion after delivery is once again a promise whose fulfilment you cannot verify from the outside. As an improvement on the current state it is relevant nonetheless, and for purchases in the EU it is worth looking before your next order to see whether the option has appeared in the checkout.

What the incident says about intermediaries in the crypto supply chain

The attack hit a provider two stations behind the manufacturer. For you as a customer that is the most uncomfortable part: you ordered from Trezor, but your data sat with a company whose name most of those affected learned only through this report. That applies to hardware wallets exactly as it does to any other online purchase.

What carries over is above all the question of how many places hold your data. With a trading platform it is the provider, the payment processor and the identity checker; with a device purchase it is the retailer, the fulfilment provider and the courier. Each is a separate point of attack, and you check none of them yourself. Anyone choosing a platform can at least look at the supervision: in a provider comparison, the question of domicile, licence and data processing now belongs to the selection just as much as the fee does.

Checking the Trezor data breach: what to take away

  1. Check your inbox first, not your wallet. A message from help@trezor.io decides whether you are affected; without it you are not in the data, according to the manufacturer. Your coins are safe regardless, as long as your backup was never typed in anywhere. If you are thinking about your device anyway, the hardware wallet comparison helps you place it.
  2. Expect targeted approaches, not mass mailings. Reckon with mails, calls and letters containing your genuine order data over the coming months. The word sequence of your backup never leaves your device. If you want to spread your custody more widely, the software wallet comparison shows what makes sense alongside the device.
  3. Reduce the data trail on your next order. A dedicated order address, a pickup point instead of your home address, buying direct from the manufacturer. And if part of your holdings sits on a platform, check in the exchange comparison who holds which data there and under whose supervision.

Sources and evidence for this article

Figures, periods, data fields and country details come from Trezor's blog post on the incident at the shipping provider, last updated on September 4, 2026. The independent assessment of the total figure and the period covered by the second wave draws on the CyberInsider report of September 4, 2026. Both sources were accessible on September 4, 2026.

(As of September 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker