Trezor told 13,689 customers on August 13, 2026 that their names, home addresses, phone numbers, and email addresses had leaked. Not because anyone breached Trezor’s servers. Not because a private key or seed phrase was touched. The break-in happened one link down the supply chain, at ShipMonk, the fulfillment company that packs and ships Trezor hardware wallets to buyers in seven countries. Combined with a parallel breach at rival vendor SafePal, the two incidents now total more than 53,000 exposed crypto hardware wallet owners, according to Forbes reporting from August 17, 2026.

The timing makes it worse. Just two weeks earlier, Coinkite’s Coldcard wallet suffered what TRM Labs calls the largest hardware wallet exploit of 2026, a $116 million firmware-level theft that started July 30. Binance co-founder Changpeng Zhao summed up the month bluntly on X: “not a great month for hardware wallets.” This article breaks down what actually happened at Trezor and SafePal, why it’s a fundamentally different threat than the Coldcard hack, what it means for anyone who owns a hardware wallet, and where the crypto custody industry goes from here.

What Happened at Trezor: The ShipMonk Breach Timeline

The chain of events starts with ShipMonk, a third-party logistics provider Trezor uses to pack and ship physical orders. According to TRM Labs and multiple outlets tracking the fallout, attackers gained unauthorized access to ShipMonk’s systems on August 8, 2026, reportedly through a Metabase analytics vulnerability. ShipMonk notified Trezor on Monday, August 10. Trezor published its public disclosure three days later, on August 13, and emailed every affected customer the same day.

The numbers Trezor released are specific: 13,689 customers total, split into two exposure tiers. Of those, 11,742 had their full name, email address, phone number, and complete shipping address exposed. The remaining 1,947 had a narrower slice leaked, just name, city, and email. The exposed order window ran from May 10 to August 8, 2026, tied directly to Trezor’s data retention policy, which had already purged anything older.

Seven countries were affected: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor’s messaging has been consistent and, by industry standards, unusually direct. The company’s blog post states plainly that no wallet secrets, seed phrases, private keys, device firmware, or on-device security were touched, and that Trezor’s own infrastructure was never accessed. It’s an identity leak, not a funds leak, and the company has repeated that distinction in every follow-up statement.

The SafePal Breach: A Parallel Incident, Same Root Cause

Trezor wasn’t alone. According to TechCrunch’s August 17 report, rival hardware wallet maker SafePal disclosed a nearly identical incident around the same week, also traced back to a shipping partner rather than SafePal’s own systems. Forbes puts the combined total of exposed records across both companies at 53,487, spanning names, emails, and physical addresses.

The pattern matters more than either individual breach. Two competing hardware wallet vendors, hit through the same category of vendor (logistics and fulfillment), within days of each other, is a signal that attackers have identified shipping and fulfillment partners as a soft entry point into an industry that has otherwise hardened its core product. Crypto hardware wallets are built around the assumption that the device itself is the trust boundary. Nobody designed the shipping label for that threat model, and now attackers don’t need to.

Multiple sources, including Forbes and Memeburn, attribute the ShipMonk intrusion to the ShinyHunters group, which reportedly exploited a SQL injection flaw in a Metabase analytics deployment to reach the underlying customer database. ShinyHunters has built a reputation this year for going after data adjacent to high-value targets rather than the targets directly, since perimeter security at a small logistics vendor is rarely as tight as at a hardware security company.

Why This Is Not the Coldcard Hack

It’s tempting to lump every August 2026 hardware wallet headline into one story. That would be a mistake, and Trezor has gone out of its way to say so. On August 4, before its own breach even became public, Trezor published a blog post titled “Coldcard vulnerability: Trezor devices are not affected,” a preemptive move that now reads almost prophetic given what happened to Trezor’s own shipping partner nine days later.

The Coldcard incident, tracked in detail by TRM Labs, is a completely different animal. Starting July 30, 2026, an attacker exploited a five-year-old firmware flaw in Coinkite’s proprietary randomness generation to systematically drain bitcoin directly from affected devices, a wallet-level compromise with direct financial loss estimated at $116 million. That’s a cryptographic and firmware failure inside the device. The Trezor and SafePal incidents are the opposite: the devices, the firmware, and the private keys were never touched. What leaked was real-world identity data sitting in a shipping company’s database.

Memeburn’s breakdown of “every hardware wallet breach of 2026” makes the same distinction its headline promises: these are not the same thing, and treating them as interchangeable actually makes people worse at protecting themselves, because the mitigation for a firmware bug (update your device, verify signatures) does nothing for a shipping-partner data leak (watch for phishing, don’t trust unsolicited mail).

Comparing the Three Major 2026 Hardware Wallet Incidents

Here’s how the three headline incidents of August 2026 stack up against each other, based on company disclosures and TRM Labs, Bloomberg, and Forbes reporting.

IncidentVendorAttack SurfaceDisclosedRecords/Funds AffectedFunds at Risk
Coldcard firmware exploitCoinkiteDevice firmware (5-year-old randomness flaw)Tracked from July 30, 2026Affected device population undisclosed~$116 million (TRM Labs)
ShipMonk/Trezor breachTrezorThird-party shipping provider (Metabase flaw)August 13, 202613,689 customer recordsNone reported
SafePal shipping breachSafePalThird-party shipping providerWeek of August 17, 2026Contributes to 53,487 combined totalNone reported

What Data Was Exposed, Field by Field

The precision of Trezor’s disclosure is worth laying out in full, since it’s a template for how a company should communicate a supply-chain breach: exact numbers, exact fields, exact time window, no vague language.

Exposure TierCustomersData Fields ExposedOrder Window
Full exposure11,742Full name, email, phone number, complete shipping addressMay 10 – Aug 8, 2026
Partial exposure1,947Name, city, email addressMay 10 – Aug 8, 2026 (some orders may fall outside this window)
Total affected13,689

Countries affected: United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, according to Trezor’s own blog post and confirmed independently by Bloomberg’s August 13 coverage.

Why a Name and Address Leak Actually Matters for Crypto Holders

No seed phrase, no private key, no funds. So why does this rank as a serious story instead of a routine data breach footnote? Because of what the data reveals in combination: a real name, a real home address, and confirmation that this specific person owns a hardware crypto wallet.

That combination is close to a target list for two categories of attack that don’t require touching any computer system at all. The first is phishing: fraudulent emails or letters that reference the person’s real order details to look legitimate, then direct them to a fake “security update” page designed to harvest a seed phrase. The second, more disturbing category is what the crypto security world calls “wrench attacks,” physical targeting of known crypto holders at their home address. Trezor’s own communications flagged this risk directly, and outside coverage from Forbes documented fraudulent physical letters already being sent to affected customers referencing their real order history.

KuCoin’s news desk noted that, as of its August 14 report, Trezor had not confirmed whether the leaked dataset was being actively sold or traded on criminal marketplaces, nor had any direct fraud or physical safety incident been tied to the leak at that point. That could change as the data circulates further; breach data typically has a long tail of downstream abuse that takes months to surface in full.

Historical Context: A Pattern Going Back to 2020

This isn’t the industry’s first brush with a shipping-adjacent breach. Ledger, Trezor’s largest competitor, suffered a widely reported e-commerce database breach in 2020 that exposed roughly a million email addresses and around 270,000 physical shipping addresses, an incident that directly led to years of phishing campaigns and multiple documented physical robberies of Ledger customers. That breach is still searched today; DataForSEO keyword data shows “ledger data breach” pulling meaningful monthly search volume in 2026, six years after the fact, evidence of how long the phishing tail runs once physical addresses tied to crypto ownership get out.

The Trezor/SafePal incident follows the same shape as Ledger 2020 almost exactly: third-party e-commerce or logistics infrastructure, not the wallet vendor’s core product, is the point of failure. Six years and one entire hardware wallet generation later, the lesson clearly hasn’t been fully absorbed industry-wide. What’s different in 2026 is speed of disclosure. Trezor went from notification (August 10) to public statement (August 13) in three days, considerably faster than Ledger’s 2020 response, which took weeks to fully detail.

Market and Industry Reaction

Unlike an exchange hack or a bridge exploit, a data breach with no funds loss doesn’t tend to move token prices, and this one hasn’t. Bitcoin traded in the $60,000–$65,000 range through most of August 2026 and analysts at Santiment noted the Trezor breach as one of several bearish headlines that month (alongside a Coinbase earnings miss and a Clarity Act delay) that nonetheless failed to push the asset meaningfully lower.

The real market impact is reputational and behavioral rather than financial. Hardware wallet vendors compete heavily on the marketing claim that they are safer than exchange custody, precisely because there’s no counterparty risk and no centralized database of your holdings to steal. A breach that proves the surrounding business (shipping, support, fulfillment) can still leak identity data undercuts that pitch even when the core security promise holds. Expect vendors to respond with visible changes to vendor due diligence, and possibly a wave of marketing around “no third-party data sharing” as a new differentiator.

Competitive Landscape: How Hardware Wallet Vendors Are Responding

Trezor’s response has been the most transparent of the three vendors caught up in August’s run of incidents. It published exact numbers, named the third party responsible, and separately pre-empted confusion with its Coldcard clarification post days before its own breach even broke. SafePal’s disclosure, per TechCrunch, arrived with less specificity about total numbers, though the company confirmed the same general shape: a shipping-partner leak, not a wallet compromise.

Coinkite’s Coldcard response centered on firmware patching rather than customer communication about data exposure, since its incident was a funds-loss event rather than an identity leak, a fundamentally different remediation path. TRM Labs’ analysis of the $116 million exploit noted the flaw had existed in Coldcard’s codebase for roughly five years before being actively exploited, raising separate questions about how thoroughly hardware wallet firmware gets audited over its lifecycle versus at launch.

What Affected Customers Should Do Now

If you bought a Trezor or SafePal device between May and August 2026, security researchers and the companies themselves recommend a specific set of steps, none of which involve moving funds or generating a new seed phrase, since the wallet itself was never compromised.

  • Treat any unexpected email, text, or physical letter referencing your Trezor or SafePal order as a phishing attempt until verified through the vendor’s official channel.
  • Never enter a seed phrase into any website, app, or “recovery tool,” regardless of how official it looks; no legitimate hardware wallet company ever asks for one.
  • Be alert to physical mail referencing your real order history, since Forbes has already documented fraudulent letters using leaked ShipMonk data.
  • Consider a mail-forwarding or PO box arrangement for future crypto hardware orders if you’re in one of the seven affected countries.
  • Monitor for account-takeover attempts on unrelated accounts, since leaked emails and phone numbers get reused across credential-stuffing campaigns.

Predictions: Where This Goes From Here

Based on how similar breaches have played out historically and the specifics of this incident, here’s how the next six to twelve months likely unfold.

  1. Phishing volume targeting the 13,689 Trezor customers will rise over the next 60-90 days, mirroring the multi-year phishing tail that followed Ledger’s 2020 breach.
  2. Expect at least one more hardware wallet vendor to disclose a shipping or fulfillment-partner breach within the next two quarters, given that ShipMonk and SafePal’s provider were hit within the same window using similar techniques.
  3. Hardware wallet vendors will start publishing formal third-party vendor security audits as a marketing and trust differentiator, similar to how exchanges now publish proof-of-reserves after 2026’s stablecoin audit push.
  4. Regulatory attention on crypto custody vendors’ data-handling practices will increase, particularly in the EU given that Sweden, Italy, and Portugal are among the seven affected countries and GDPR notification obligations apply.
  5. Firmware-level audits like the one that would have caught Coldcard’s five-year-old flaw will become a competitive talking point, with vendors publicizing third-party security audit results more aggressively than before.

For more crypto security coverage, visit our cryptocurrency section.

Frequently Asked Questions

Did the Trezor breach expose my seed phrase or private keys?

No. Trezor has stated repeatedly that no wallet secrets, seed phrases, private keys, firmware, or on-device security mechanisms were compromised. The breach occurred at ShipMonk, a shipping provider, and exposed only order and contact data.

How many people were affected by the Trezor data breach?

13,689 customers total: 11,742 with full exposure (name, email, phone, address) and 1,947 with partial exposure (name, city, email), according to Trezor’s official disclosure.

Is the Trezor breach the same as the Coldcard hack?

No. The Coldcard incident was a firmware-level exploit that drained funds directly from devices, roughly $116 million according to TRM Labs. The Trezor and SafePal incidents were data breaches at shipping partners that exposed customer identity information, not device or fund compromises.

Which countries were affected by the Trezor/ShipMonk breach?

The United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, covering customers who placed orders between May 10 and August 8, 2026.

Was SafePal affected by the same attack as Trezor?

SafePal disclosed a separate but similar incident around the same period, also tied to a shipping/logistics partner rather than SafePal’s own core systems. Combined, Forbes reports the two breaches expose over 53,000 customer records.

What should I do if I’m one of the affected Trezor customers?

Treat unsolicited emails, texts, and physical mail referencing your order as potential phishing, never enter your seed phrase anywhere online, and watch for account-takeover attempts using the leaked email and phone data on unrelated services.

Who was responsible for the ShipMonk breach?

Multiple reports, including Forbes and Memeburn, attribute the intrusion to the ShinyHunters group, who reportedly exploited a Metabase SQL injection flaw in ShipMonk’s analytics systems to reach customer order data.

Did the Trezor breach affect Bitcoin’s price?

No significant, isolated price impact has been reported. Bitcoin traded in the $60,000–$65,000 range through August 2026, and analysts at Santiment listed the breach as one of several bearish headlines that month that didn’t independently move the market.