Nobody Broke Into Trezor. They Broke Into the Company That Mailed the Boxes
A SQL injection flaw in an analytics tool used by Trezor's shipping partner exposed the names, home addresses and phone numbers of 13,689 hardware wallet owners. No seed was stolen. Something arguably more dangerous was.

The thing worth understanding about this one is that it is not a wallet breach, and calling it one gets the danger backwards.
On August 13, 2026, Trezor disclosed that 13,689 of its customers had their personal details exposed. No Trezor device was compromised. No seed phrase left a chip. Trezor's own infrastructure was never touched. What leaked was the paperwork wrapped around the hardware: full names, email addresses, phone numbers, shipping addresses, and order numbers for 11,742 customers, plus partial records covering name, city and email for another 1,947.
The breach happened three companies deep. Trezor ships through ShipMonk, a fulfilment provider. ShipMonk runs Metabase, a third-party analytics platform. Metabase had a SQL injection flaw in its password reset handling, where the request body did not restrict undeclared fields, and an attacker used that to inject commands and take full administrator control of the database underneath. From there, exfiltrating ShipMonk's customer order data was a query.
The timeline says something uncomfortable about how long a zero-day stays useful. The flaw was first exploited on August 3, before it was public. Metabase disclosed and patched it roughly a week later. Metabase told ShipMonk on August 6 that an unauthorized party had used the flaw to reach data tied to ShipMonk's account and its customers. ShipMonk told Trezor on Monday, August 10. Trezor told its customers on Thursday, August 13. Every link in that chain behaved reasonably and the customer still found out ten days after the fact.
The exposure window covers orders placed between May 10 and August 8, 2026, across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Anyone who bought through Amazon was spared, because those orders went through a different logistics provider entirely.
Researchers attributed the extortion phase to ShinyHunters, a group with a long record of hitting SaaS and fintech companies, though the technical artifacts supporting that attribution have not been published.
Trezor's messaging was clear and, on the narrow point, correct. "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts." Nothing in the leak gives anyone the ability to move funds. A hardware wallet's security lives in a private key generated inside a secure element, and a shipping database has no relationship to it.
Here is why that reassurance only covers half the problem.
This is the first breach in Trezor's history to expose customer phone numbers and home addresses together. Put those two fields beside a purchase record for a Bitcoin hardware wallet and you have produced a list of named individuals, at verified street addresses, reachable by phone, who are known to hold cryptocurrency in self-custody. Phishing is the obvious risk and the one Trezor named. It is not the worst one.
Ledger's customer database leaked in July 2020 with the same categories of information. What followed was years of targeted phishing, then physical attacks against named holders, then the phrase "wrench attack" entering the vocabulary of an entire industry. The data outlives the incident. Six years on, that list is still circulating and still being worked.
What can actually be done about it is thin, and that is worth stating rather than glossing. A leaked email can be filtered. A leaked phone number can be changed, with effort. A leaked home address cannot be changed by anyone who is not willing to move house. Trezor apologised, confirmed its systems were secure, and advised vigilance against phishing. It did not offer credit monitoring, address-change support, or anything else addressing the category of harm that the combination of fields actually creates. Vigilance is reasonable advice against a fraudulent email. It is not advice at all against somebody knocking on the door.
No funds were stolen here, so the dollar figure on this entry is zero. The correct way to read that number is that the loss has not happened yet.
The Aftermath
Trezor apologised, confirmed its own systems and devices were unaffected, and warned customers to expect more sophisticated phishing. It has not offered credit monitoring or address-change assistance, which are the remedies that would actually matter for people whose home addresses are now in circulation. The Metabase flaw is patched. The data is not recoverable and does not expire; Ledger's equivalent 2020 leak is still being used against named holders six years later. No arrests have been reported in connection with the ShipMonk intrusion.
COMMENTS