Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Whether you are affected by the Trezor data breach comes down to a single question: is there an email from help@trezor.io about the incident in your inbox? Trezor says it notifies every affected person individually. Anyone who has not received that message is, according to the manufacturer, not in the exposed records.
On September 4, 2026, Trezor widened the incident for the second time. Around 67,000 further customers in the United States were added to the 13,689 reported in August, bringing the total to just over 80,000 people. Exposed were the full name, delivery address, phone number, email address and order number. Not exposed were the contents of the parcels, the devices themselves, private keys or wallet backups.
This article answers the question behind the headline that nobody has answered in German so far: whether German customers appear in this second wave at all, how you check that, and what an open address book means for someone who holds crypto assets in self-custody.
Am I affected by the Trezor data breach? The check takes two minutes
Trezor has taken the same route for both waves: those affected are informed directly by email, sent from help@trezor.io. The sentence appears verbatim in the blog post on the incident, and it works in both directions. No mail from that address means, in the manufacturer's account, that you are not affected.
The notification itself distinguishes two levels. With full exposure, the name, email address, phone number and delivery address are affected. With partial exposure, it is only the name, city and email address, with the street address missing. Which of the two applies to you is stated in the mail. That is not a formality: an exposed street address weighs considerably more heavily than an exposed city.
And if you are not sure about the mail
This is exactly where the real risk begins. A data breach that is reported publicly is an invitation to fraudsters, because thousands of people are expecting a warning email right now. So check the sender address character by character, open no attachments and follow no link from the mail. If you want to know whether a message is genuine, call up the Trezor site yourself through your browser's address bar and look for the blog post on the incident there. The route via the address bar is the only one an attacker cannot fake.
What was exposed at ShipMonk and what was not
ShipMonk is a fulfilment provider, a company that stores a manufacturer's goods, packs orders and ships them to customers. For that job such a provider needs precisely the data that has now leaked: name, delivery address, phone number for the courier, email address and order number. Trezor describes ShipMonk as one of its shipping partners for the United States, the United Kingdom and other countries.
On August 10, 2026, ShipMonk reported unauthorised access to systems holding customer data to the manufacturer. Trezor made the incident public on August 13. What was expressly not affected is the more important part of the disclosure: Trezor's own systems were not compromised, according to the company, the devices are safe, and private keys and wallet backups are untouched. The contents of the parcels do not appear in the data either. An attacker therefore knows that an order went to a particular address, but not which device was in it or how much sits on it today.
Why this still concerns you as a self-custodian
A hardware wallet is a device that keeps your private keys permanently offline and signs transactions only after confirmation on the device itself. That makes it the standard tool of self-custody, and it carries one unavoidable side effect: it remains a physical product. Anyone who buys one has to have it delivered, and in doing so leaves a name, an address and a phone number with at least one intermediary. That is exactly the trail exposed here. If you are currently weighing up which device and which purchase route suits you, the hardware wallet comparison helps with the choice. Since this incident, the data trail left by an order belongs among the criteria that go into that decision.

Why Germany appears on neither list of affected customers
Trezor names the countries affected in both waves, and the result is unambiguous for German readers. The first wave covered orders from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, delivered between May 10 and August 8, 2026. The second wave affects customers in the United States exclusively, according to the manufacturer. Germany appears in neither list.
That is a piece of information with a limit, and the limit belongs with it. What counts is the delivery address, not the place of residence or nationality. Anyone who had a device sent to an address in one of the countries named can be affected even if they live in Germany. And the country list does not replace the check: what matters remains the notification from help@trezor.io.
Hardware Wallets Compared: Which Device Suits YouThe second wave hits an entirely different group of buyers
The real finding in this update is not the number but the period. The first wave concerned fresh orders from the spring and summer of 2026. The roughly 67,000 new records come from an earlier collaboration between November 2019 and August 2021. These are people who ordered a device four to seven years ago and may never have bought there again since.
For this group the situation reverses. Anyone who read the first report in August 2026 and found that their last order was years back had good reason to consider themselves unaffected. Since September 4 that no longer holds. Our report on the first wave of the ShipMonk data breach gives the figure of 13,689 affected customers that applied at the time. That number has been overtaken by the update; the sequence of events and the mechanics described there hold unchanged.
Why this is more than a revised figure: the second wave consists throughout of full exposures, according to Trezor, so name, email, phone number, delivery address and order number as one package. And it hits orders from a time when crypto assets were worth considerably less than they are today. Someone who bought in 2020 and held is statistically sitting on a larger balance than someone who came in during 2026. Any attacker makes that connection unaided.
Deletion confirmed in writing, data present anyway
Trezor works, by its own account, with a retention period of 90 days: order data is to be deleted or anonymised 90 days after delivery, and the company says it agreed the same condition with its shipping partners. In the report of August 13 that very period was cited as the reason the damage was limited.
The update of September 4 pulls the ground out from under that argument. Trezor writes that it repeatedly requested, and received, written confirmation of deletion throughout the collaboration, and that it is deeply disappointed the data was not deleted in the provider's systems despite that confirmation. This account comes from the manufacturer; a statement from the provider on the matter is not available to us.
What you take from this for every other provider
The point generalises, which makes it the practically most valuable one in the whole affair: a contractual deletion period is a promise, not a guarantee. The contract describes what a provider is supposed to do, and says nothing about what is actually still sitting in its databases. You cannot check that from the outside. What you can control is the volume of data you hand over in the first place, and that is what the later part of this article is about.
Why an address leak is not a crypto loss
This distinction is the reason you do not need to move any coins after this report. An attacker who knows your name, your address and your phone number has no access whatsoever to your holdings. Access hangs solely on the wallet backup, the sequence of words your device displayed during setup and from which all private keys can be restored. That word sequence was never held by the shipping provider and is not part of the leak.
Anyone holding Bitcoin or other crypto assets on their own device therefore has no technical reason to swap the device or move holdings after this incident. A wallet whose backup was never recorded digitally and never typed in anywhere stays safe even if the delivery address is public. Only one thing has changed: the probability of being approached in a targeted way.

How to spot phishing after a data breach: the signs that count
Phishing describes the attempt to get you to hand over access credentials or keys through a faked message. After an address leak it becomes precision work: someone who knows your name, address, phone number and order number no longer writes a mass mail but composes a message containing genuine personal details, which is why it reads as credible. Trezor points explicitly to this heightened risk in its own blog post and names faked emails, fraudulent calls and letters.
How you recognise such a message:
- Urgency. Any message demanding immediate action because something is supposedly blocked, compromised or lost belongs on the test bench. Time pressure is the tool used to prevent checking.
- A request for recovery data. No reputable manufacturer ever asks for your wallet backup, your word sequence or your private key, not by mail, not on the phone and not on a website.
- Personal details as a trust anchor. After this leak, an address and an order number are no longer proof of authenticity but an indication that someone is working with leaked data.
- The link goes somewhere other than it promises. Hover over the link without clicking and read the actual destination. On a phone, a long press rather than a tap does the job.
- A device arrives unrequested. Anyone who receives a supposedly free or replacement device by post after a leak should not set it up. Tampered devices carrying a ready-made backup are a known line of attack.
- The call comes from support. Phone numbers are part of the leak. A call back on a number you looked up yourself on the manufacturer's site settles any doubt.
How concrete this can get is shown by the case we described in our article on phishing letters sent to wallet owners: there the attack reached its targets as a printed letter carrying the appearance of an official demand. An exposed home address is what makes that route possible in the first place.
Wallet backup: the one rule every attack fails against
The wallet backup is the recovery sequence of usually twelve or twenty-four words with which your entire wallet can be rebuilt on any other device. Whoever has it has the coins. Hence one rule that holds without exception: these words are never entered on a website, never photographed, never stored in a cloud and never told to anyone, support staff included.
This single rule neutralises practically every attack that follows from an address leak. An attacker can write to you, call you, impress you with your order number and show you a perfectly rebuilt page. As long as the word sequence does not leave your device, the attack has no effect. While you are at it, check where your backup physically sits and whether it would survive water damage or a house fire there.
An exposed home address: what the physical risk means in practice
Alongside phishing, Trezor explicitly names possible risks to the physical safety of those affected in its updated report, and trade media have picked the point up. It is the sober consequence of a data combination: a list of home addresses behind which someone holding crypto assets very probably stands is a different thing from a furniture retailer's customer address list.
In practice that means restraint above all. Anyone who talks publicly about their own holdings, shows them on social networks or appears under their real name in the relevant forums links the leaked address to an order of magnitude. That link is the actual risk factor, and it is the only variable in the equation you still control yourself. Where your backup sits is likewise nobody's business, and a location outside the home has a second advantage here beyond fire protection.
How to order a hardware wallet with a smaller data trail
Trezor itself lists several ways to give away less about yourself when buying. None is restricted to one manufacturer; all of them work with any mail-order retailer:
- A dedicated email address for orders that does not carry your name and is linked to no other account.
- Payment in cryptocurrency where the retailer offers it, otherwise a virtual single-use card instead of your main credit card.
- A pickup address instead of your home address. Trezor names the PO box; in Germany a parcel locker or branch delivery is also an option. Collection usually requires ID, and the courier stores that data in turn.
- Buying from the manufacturer rather than through marketplaces. That does not reduce the volume of data, but it does reduce the number of places holding it, and it rules out tampered second-hand devices.
The rest is a trade-off. Each of these measures costs convenience, and none of them makes you invisible. Anyone who wants to avoid the data aspect entirely arrives at a different form of custody: a software wallet is an application on a phone or a computer that stores the keys locally. Such an application is downloaded rather than delivered, so it leaves no delivery address, but it offers less protection against malware on the machine. Which application does what is set out in the software wallet comparison; for larger holdings the combination of both remains the usual route.
What Anonymous Delivery is and when Trezor plans to offer it in Europe
In the same blog post Trezor announces a shipping option called Anonymous Delivery: a separate ordering process with collection at a pickup point, neutral packaging, generic sender details and automatic deletion of the shipping identifiers after delivery. For the European Union the company gives September 2026 as its target, and the end of the year for the United States.
Two qualifications belong with that. First, this is a manufacturer's announcement and not an available product; whether the date holds cannot be checked today. Second, the option solves the underlying problem only in part: even with neutral packaging a courier needs a destination address, and deletion after delivery is once again a promise whose fulfilment you cannot verify from the outside. As an improvement on the current state it is relevant nonetheless, and for purchases in the EU it is worth looking before your next order to see whether the option has appeared in the checkout.
What the incident says about intermediaries in the crypto supply chain
The attack hit a provider two stations behind the manufacturer. For you as a customer that is the most uncomfortable part: you ordered from Trezor, but your data sat with a company whose name most of those affected learned only through this report. That applies to hardware wallets exactly as it does to any other online purchase.
What carries over is above all the question of how many places hold your data. With a trading platform it is the provider, the payment processor and the identity checker; with a device purchase it is the retailer, the fulfilment provider and the courier. Each is a separate point of attack, and you check none of them yourself. Anyone choosing a platform can at least look at the supervision: in a provider comparison, the question of domicile, licence and data processing now belongs to the selection just as much as the fee does.
Checking the Trezor data breach: what to take away
- Check your inbox first, not your wallet. A message from help@trezor.io decides whether you are affected; without it you are not in the data, according to the manufacturer. Your coins are safe regardless, as long as your backup was never typed in anywhere. If you are thinking about your device anyway, the hardware wallet comparison helps you place it.
- Expect targeted approaches, not mass mailings. Reckon with mails, calls and letters containing your genuine order data over the coming months. The word sequence of your backup never leaves your device. If you want to spread your custody more widely, the software wallet comparison shows what makes sense alongside the device.
- Reduce the data trail on your next order. A dedicated order address, a pickup point instead of your home address, buying direct from the manufacturer. And if part of your holdings sits on a platform, check in the exchange comparison who holds which data there and under whose supervision.
Sources and evidence for this article
Figures, periods, data fields and country details come from Trezor's blog post on the incident at the shipping provider, last updated on September 4, 2026. The independent assessment of the total figure and the period covered by the second wave draws on the CyberInsider report of September 4, 2026. Both sources were accessible on September 4, 2026.
(As of September 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
- Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
April 27, 2026 10:30 AM

Win $5,000 in BTC: Tangem Launches Exclusive 2026 Prize Draw
Tangem announces a massive prize draw with $5,000 in BTC and iPhone 17s up for grabs. Secure your crypto and enter today using our exclusive link.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
More from CryptoTicker
