80,700 Trezor Buyers Just Had Their Home Addresses Leaked. No Wallet Was Touched, and That Is Not the Point

Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Breach Published September 10, 2026 · 8 min read · By Yongrui Sun
80,700 Trezor Buyers Just Had Their Home Addresses Leaked. No Wallet Was Touched, and That Is Not the Point
80,700 Trezor Buyers Just Had Their Home Addresses Leaked. No Wallet Was Touched, and That Is Not the Point

The whole pitch of a hardware wallet is that the keys never touch a networked computer. Someone on another continent can send you phishing email all week and still end up with nothing, because the seed phrase is written on a card in a drawer. On September 4, 2026, Trezor disclosed a breach that respects that boundary completely — and makes the one attack a hardware wallet cannot stop substantially easier to carry out.

The company's fulfillment vendor, ShipMonk, was breached. The exposure now covers roughly 80,700 US customers, up from the roughly 13,700 Trezor first disclosed on August 13. The fields are full name, email address, phone number, and home shipping address, tied to orders placed between November 2019 and August 2021.

No wallet was compromised. No private keys, no seed phrases, no funds lost. Trezor's own systems were never breached. Every one of those sentences is true, and for 80,700 people none of them is the sentence that matters.

Editor’s take: What incident reports keep showing: budget twice the time for internal coordination and training, not for the tool. The tool is the easy part.

Editor's Take

The whole value proposition of a hardware wallet is that keys never touch a networked machine, and this breach did not contradict that — no wallet was accessed. What it did expose is the part people forget: the physical world around a crypto holder. A home address tied to a known hardware wallet purchase is a burglary and extortion risk, which is a threat model no amount of key hygiene addresses.

Read That Field List Again, in Order

Most breaches leak credentials or contact details, and the advice that follows is built around replacement: change the password, cancel the card. This leak contains no replaceable secret at all. It contains four ordinary facts about a person, and the damage is in how they combine.

A name and an email address get you phishing. A name, a phone number and a home address, attached to the purchase of a device whose only function is holding cryptocurrency, get you something else: a list of households that almost certainly hold crypto, with the door number already written down.

That is the entire reconnaissance problem solved. Criminals looking for physical targets have historically had to do the slow work of finding people worth robbing — exchange leaks, forum posts, conference photos, on-chain tracing. Here the filter is pre-applied. Everyone on this list bought a hardware wallet, which means everyone on this list self-identified as someone with assets worth protecting offline.

The Physical Risk Is Not Hypothetical Anymore

Security researchers call these wrench attacks: instead of defeating the cryptography, you use violence, home invasion or kidnapping to compel the person who holds the keys to hand them over. The encryption is irrelevant. So is the quality of your seed phrase storage.

CertiK's figures for the first half of 2026 should be read by anyone on this list:

The concentration is European, and France alone accounts for 33 of the 52. That is worth stating plainly rather than using it as reassurance: the Trezor list is US customers, and the surge CertiK documented is somewhere else. But the mechanics do not care about borders. A crew that assembles target packages from leaked databases will use a US list the same way it uses a French one, and home invasion — the tactic that grew from one case to twenty in a year — is the tactic that needs an address.

A Dashboard, Not a Heist

The entry point is almost insultingly mundane. ShipMonk used Metabase, a business analytics tool, to query its own databases. Metabase had a SQL injection zero-day, CVE-2026-72898, rated CVSS 10.0.

The extortion group ShinyHunters used it to create administrator-level sessions and bulk-download customer data tables, then contacted ShipMonk directly with extortion demands.

Nobody fell for an email. Nobody reused a password. No employee was socially engineered. An internal reporting tool sat in the path of everything, and one unpatched flaw in it was enough to pull years of shipping records out in bulk. This is the same shape as the BigBear credential operation in one respect: the defenders were watching the front door, and the loss happened through a side system nobody in the security programme owned.

"We Asked. They Said It Was Deleted."

Here is the part that should bother people more than the vulnerability.

Trezor says it repeatedly asked ShipMonk to confirm that older order records had been deleted, and received written assurance that they had been. They had not been. The data was still sitting there years after the business relationship it came from had ended.

That is a governance failure with a very long half-life. A zero-day gets patched and the exposure window closes. Retention that was promised and not performed means the data sat in a reachable system every single day for years, waiting for whichever vulnerability eventually arrived. The breach was not caused by the decision to keep the data, but keeping the data is what made the breach worth 80,700 records instead of zero.

And the written assurance is the detail to sit with. Organisations treat vendor attestation as a control, but an attestation is a claim, not a deletion. Until someone can prove a record is gone from the analytics replica and the backup as well as the primary table, "we deleted it" is a sentence with no mechanism behind it.

What To Do If Your Address Is In It

The part still under your control: what an attacker can find when they look up your street address. The order record is gone, but broker listings are what turn a name and a door number into a full profile of a household.

Check PrivacyHawk pricing

This is the second time in a month Trezor has had to expand this disclosure, which is itself worth noting: the first number was wrong, and the corrected number came with the field that actually matters. For the general triage sequence after any exposure, our data breach response guide walks through it in order, and our phishing identification guide covers the specific tells in a message. The IDScan driver's license breach is the parallel case where the exposed data also could not be reissued.

The Honest Read

Trezor's security held. There is no evidence anywhere in this incident that the company did something careless with keys, firmware or customer credentials. What failed was one hop out: a warehouse company with an old spreadsheet's worth of addresses and an analytics tool nobody patched.

That is the uncomfortable shape of modern breaches. You can do everything right — short retention policy, contractual deletion requirements, and the discipline to ask for written confirmation — and still end up on the wrong side of a headline, because the organisation that actually holds your data is not the one whose name you chose to trust.

For the people on this list, the practical takeaway is not "Trezor is unsafe." It is that a hardware wallet protects you from every attacker except the one who knows where you live, and 80,700 of you just had that information handed to a group that sells it.

YS
Founder & Editor

CyberPicks is published by Yongrui Sun. Every comparison is built from vendor documentation, published pricing, published specifications, and published independent-lab results. We do not run hands-on lab tests, and where a figure comes from a vendor or an independent testing lab we say which on the page.

Sources

How we compared

This report is based on published notifications and reporting about the incident.

Frequently asked questions

Were any Trezor wallets or seed phrases compromised?

No. Trezor says no private keys, no seed phrases and no funds were affected, and that its own systems were never breached. The incident was entirely inside ShipMonk, the third-party fulfillment vendor that handled shipping.

What data was exposed in the ShipMonk breach?

Full names, email addresses, phone numbers and home shipping addresses, tied to orders placed between November 2019 and August 2021. Trezor put the total at roughly 80,700 US customers on September 4, 2026, up from about 13,700 disclosed on August 13.

How did attackers get into ShipMonk?

ShipMonk used Metabase, an analytics tool, which had a SQL injection zero-day tracked as CVE-2026-72898 and rated CVSS 10.0. The extortion group ShinyHunters exploited it to create administrator-level sessions and bulk-download customer data tables, then sent extortion demands to ShipMonk directly.

Why is a leaked home address worse than a leaked email address?

An email address produces phishing. A home address, cross-referenced against a confirmed hardware wallet purchase, produces a physical target list. CertiK verified 52 wrench attacks in the first half of 2026, up 33% from 39, with home invasions rising from one publicly reported case to 20.

Did Trezor ask ShipMonk to delete the data?

Yes. Trezor says it repeatedly asked ShipMonk to confirm that older order records had been deleted and received written assurance that they had been. They had not been. The data was still retained years after the business relationship it came from had ended.

What should affected customers do now?

Treat any unsolicited contact from Trezor or ShipMonk as hostile, never follow links in it, navigate to the official site directly, refuse any request for a seed phrase, and reduce what data brokers hold about your address so the leaked record cannot be joined to the rest of your life.

80,700 Trezor Buyers Just Had Their Home Addresses Leaked. No Wallet Was Touched, and That Is Not the Point
80,700 Trezor Buyers Just Had Their Home Addresses Leaked. No Wallet Was Touched, and That Is Not the Point — comparison snapshot