A person sealing a shipping label on a cardboard parcel

Trezor’s 81,000-Customer Breach Shows the Hardware Wallet Risk Outside the Device

September 12, 2026 3:25 pm Comments

A hardware wallet can keep the private keys locked down and still leave its owner exposed somewhere else.

Trezor’s latest disclosure makes that uncomfortable distinction impossible to ignore. The company says its devices and internal systems stayed secure even as a shipping partner exposed customer order records.

CryptoSlate focused on the security gap created by the ordinary shipping label. Buying a hardware wallet can leave a trail containing a real name, home address, phone number, email address and order number—the exact combination that can tell an attacker both who to target and where to find that person.

The danger can outlast the delivery by years. Trezor said the newly identified U.S. customers placed orders between November 2019 and August 2021, showing how a record that should have become useless after fulfillment can remain a live security liability long after the box is opened.

The exposed records do not prove that those customers still own Bitcoin, and they reveal no wallet balance or recovery seed. A criminal still has enough information to launch a convincing phishing email, impersonation call, fraudulent letter or physical threat against someone known to have purchased a self-custody device.

BleepingComputer reported that the expanded ShipMonk incident now affects roughly 81,000 Trezor customers in total. Trezor initially disclosed nearly 14,000 affected customers in August, then said another 67,000 U.S. buyers were added after the shipping provider found older records.

The newly identified group had ordered between late 2019 and August 2021. Trezor said names, email addresses, phone numbers, shipping addresses and order numbers were exposed, while wallet backups and recovery seeds were not.

The retention failure is the part that deserves special attention. Trezor says it repeatedly requested and received written assurances that older order data had been deleted under its contract and data policy, yet the records remained in the provider’s systems.

That turns a vendor promise into a security control that evidently was not verified well enough. For a Bitcoin company, deleting old customer data can matter as much as encrypting current data because the safest database for an attacker is the one that no longer exists.

The hardware-wallet industry received another warning this week from a separate vendor incident. BitBox said a phishing email sent to newsletter subscribers likely followed a compromise at its newsletter provider, and that multiple Bitcoin companies appeared to share the affected service.

The BitBox event has not been shown to be connected to ShipMonk, and the exposed data may be different. The common lesson is that a wallet company’s security boundary extends through logistics, email, customer support and every other vendor that receives information about buyers.

For customers, the immediate defense is skepticism. Do not enter a recovery phrase on a website, do not provide it over the phone, and treat unexpected security notices as hostile until they are confirmed through a company’s official site.

For wallet makers, the harder answer is data minimization backed by proof. Short retention windows, anonymous pickup options, neutral packaging and recurring deletion audits can reduce the amount of information available when a vendor is breached.

Self-custody removes a bank from control of the keys. It does not automatically remove the delivery company, email provider or forgotten customer database from the threat model.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.