Trezor customers are getting phone calls from strangers who know their home address, their name, and the fact that they own a hardware crypto wallet. Some are receiving physical letters with QR codes tucked inside. Neither is an accident. Both trace back to a breach at ShipMonk, the fulfillment company that packs and ships Trezor devices, and the scope of that breach just got a lot bigger than anyone said in August.
SatoshiLabs, the company behind Trezor, first disclosed the incident on August 13, 2026, telling roughly 13,689 customers their contact details had leaked. On September 4, the company came back with a second notice: an additional 67,000 US customers, from orders placed between November 2019 and August 2021, were also exposed. That update, combined with fresh reporting from Help Net Security on September 8 describing customers fielding phishing calls and fraudulent letters, is the story now. This is not a rehash of the August disclosure. It is what happens three to four weeks after a supply-chain breach, when the stolen data starts getting used.
Trezor Data Breach: What Changed This Week
The headline number for the Trezor data breach jumped from under 14,000 to roughly 80,689 people once the two disclosures are added together. That is not a rounding correction. SatoshiLabs said it learned two days before its September 4 update that ShipMonk had failed to purge an older set of order records covering a prior partnership period, November 2019 through August 2021, and that those records were part of the same intrusion. The company had required ShipMonk to delete or anonymize customer data after 90 days. That policy evidently was not applied to the older archive.
What makes the September 8 update different from the original disclosure is not the count, though. It is the shift from “your data was exposed” to “your data is being used.” Help Net Security reported that affected customers have started describing phishing calls and letters containing QR codes, arriving at the same addresses tied to their Trezor orders. That is the practical risk hardware-wallet owners were warned about in August finally showing up in mailboxes and on caller ID.
The ShipMonk Timeline, Start to Finish
ShipMonk detected unauthorized access to its systems around August 10, 2026. SatoshiLabs disclosed the breach to customers three days later, on August 13, covering orders shipped between May 10 and August 8, 2026, to buyers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. At that point the company said 11,742 customers had full personal data exposed (name, email, phone number, shipping address) and another 1,947 had partial exposure (name, city, email), for a combined 13,689 people.
The story sat quiet for roughly three weeks. Then, on September 4, SatoshiLabs told customers the incident was bigger: about 67,000 additional US buyers, this time from a separate, older order archive tied to a 2019-2021 ShipMonk engagement, had also been exposed. Unlike the May-August 2026 window, this batch was fully exposed data across the board, names, phone numbers, email addresses, and home addresses. Four days later, Help Net Security’s reporting captured the next stage: real-world phishing attempts hitting the people on that list.
Inside the Metabase Zero-Day That Started It
The technical root of the ShipMonk breach, according to reporting from The Hacker News and cybersecurity outlet Rescana, is a critical SQL injection zero-day in Metabase, the business-intelligence and analytics tool ShipMonk used to query its own operational data. The flaw is tracked as CVE-2026-72898 and carries a maximum CVSS severity score of 10.0. A perfect 10.0 score means an attacker needed no special privileges, no user interaction, and could reach the vulnerable component directly, which lines up with how quickly the intrusion reportedly moved from initial access to bulk data exposure.
CVE ID: CVE-2026-72898
Component: Metabase (Cloud SaaS BI platform)
Vulnerability: SQL injection
CVSS score: 10.0 (Critical)
Vector: Unauthenticated, network-reachable
Impact: Unauthorized read access to connected customer databases
Downstream: ShipMonk order/customer records exposed
Metabase sits between a company’s raw databases and the dashboards its staff use to check order volumes, shipping status, and customer records. A SQL injection bug in that layer does not just expose one table, it can expose whatever the BI tool was configured to query, which is consistent with the breadth of the ShipMonk leak spanning multiple years of order history rather than a single recent batch.
What Data Was Exposed, and What Was Not
Across both disclosures, the exposed fields are consistent: full names, email addresses, phone numbers, home shipping addresses, and order numbers. For the September batch, the exposure was described as full across the board rather than split into partial and full tiers like the August group. SatoshiLabs has been explicit on one point in both notices: Trezor’s own infrastructure was not touched. No wallet backups, seed phrases, private keys, or device firmware were part of the exposed dataset, and the company says there is no indication device security was compromised.
That distinction matters, but it should not be read as “nothing to worry about.” A crypto data breach that leaks a name, a home address, and confirmation that the person owns a hardware wallet is a targeting list, not a wallet compromise. It tells a scammer exactly who owns meaningful crypto holdings and where to find them, which is a different and in some ways more dangerous kind of exposure than a leaked password.
Phishing Calls, Fake Letters, and QR Codes
Help Net Security’s September 8 report is the clearest look yet at how the leaked data is being weaponized. Affected customers described receiving phishing calls referencing their real order details, and physical letters containing QR codes designed to look like official Trezor communications. SatoshiLabs has warned that attackers may also send phishing emails or attempt to impersonate the company directly, using the combination of name, address, phone number, and known wallet ownership to make the approach convincing.
The letter-and-QR-code method is worth pausing on because it sidesteps most of the defenses people associate with phishing. Email filters, spam blockers, and browser warnings do nothing against a physical envelope. A QR code printed on paper that claims to be a “security verification” step from Trezor can route a scanned phone straight to a fake wallet-recovery page asking for a seed phrase. Anyone who receives unsolicited mail referencing a Trezor order should treat it as hostile by default and never scan an included QR code.
Who’s Behind the Attack: The ShinyHunters Link
Enterprise blockchain security firm Holborn has attributed the ShipMonk intrusion to ShinyHunters, an extortion-focused group that has been one of the most active names in 2026’s breach cycle. ShinyHunters has been tied to a string of large-scale data-theft incidents against companies across retail, healthcare, and technology this year, typically favoring bulk exfiltration of customer records followed by extortion demands rather than ransomware encryption. If that attribution holds, the ShipMonk breach fits a now-familiar pattern: hit a smaller vendor with weaker defenses to reach the customer data of larger, better-defended brands that depend on it.
Trezor’s Response and What SatoshiLabs Is Telling Customers
SatoshiLabs has been notifying newly affected customers directly from its [email protected] address and has published details of the incident on the company’s own blog. The company’s core message across both disclosures has stayed consistent: Trezor devices are safe to keep using, no device-level or wallet-recovery data was involved, and the actual risk is social engineering, not a wallet compromise. The company has told customers to expect and ignore unsolicited contact referencing their Trezor purchase, whether by phone, email, or mail, and to never enter a recovery seed anywhere outside the physical device itself.
What SatoshiLabs has not addressed publicly, at least not in the reporting available so far, is why a shipping partner was still holding five-to-seven-year-old order records well past the 90-day retention window the company says it requires. That gap between stated policy and what actually happened at ShipMonk is likely to be the sharpest question the company faces as the story develops.
Historical Context: Hardware Wallets Keep Losing the Same Way
This is not the first time a hardware wallet company has been burned by a partner rather than its own product. Ledger’s 2020 e-commerce and marketing database breach, which exposed roughly 270,000 customers’ shipping addresses and contact details, remains the reference case in the industry: Ledger’s devices were never compromised, but the leaked address list was later linked to years of targeted phishing, home break-ins, and even physical threats against known crypto holders. The pattern in the Trezor-ShipMonk incident, a secure device paired with a leaky logistics partner, is close to a repeat of that same failure mode six years later.
2026 has already been a rough year for hardware wallet security more broadly. SafePal disclosed a separate breach around the same time as Trezor’s original August notice, and Coinkite’s Coldcard wallet was hit by a firmware-level exploit in late July that TRM Labs described as the largest hardware wallet theft of the year in dollar terms. None of these three incidents share a root cause, but together they point to the same conclusion: the wallet itself is usually the hardest part of the chain to break, so attackers are going after everything around it instead, fulfillment vendors, firmware pipelines, and now, apparently, years-old customer databases nobody remembered to delete.
Competitive Comparison: How the Trezor Breach Stacks Up
Placed next to other 2026 hardware wallet incidents and the 2020 Ledger case, the Trezor-ShipMonk breach is notable less for its size and more for its source. It is the only one of the group that originated entirely outside the wallet maker’s own infrastructure, in a third-party fulfillment system, and the only one where the exposed dataset spans multiple years of historical orders rather than a single recent batch.
| Incident | Company | Date | Root Cause | What Was Exposed |
|---|---|---|---|---|
| ShipMonk breach (initial) | Trezor / SatoshiLabs | Aug 13, 2026 | Third-party logistics partner breach | 13,689 customers’ names, emails, phones, addresses |
| ShipMonk breach (expanded) | Trezor / SatoshiLabs | Sept 4, 2026 | Undeleted historical order archive (2019-2021) | 67,000 additional US customers’ full contact data |
| SafePal breach | SafePal | Aug 2026 | Separate vendor-side incident | Customer contact and order records |
| Coldcard exploit | Coinkite | July 30, 2026 | Firmware-level exploit | ~$116M in funds, per TRM Labs |
| E-commerce database breach | Ledger | 2020 | Marketing/e-commerce database breach | ~270,000 customers’ shipping and contact data |
The wallet-security fundamentals have not really moved since 2020. Devices from Trezor, Ledger, SafePal, and Coinkite all still rely on offline seed generation and on-device transaction signing as their core protection. What keeps failing is everything wrapped around that core: the vendors, contractors, and databases that touch a customer’s name and address on the way to their front door.
Trezor Breach by the Numbers
| Metric | Figure |
|---|---|
| Customers exposed, August disclosure | 13,689 (11,742 full, 1,947 partial) |
| Customers exposed, September update | ~67,000 (US only) |
| Combined customers affected to date | ~80,689 |
| Order window, initial disclosure | May 10 – Aug 8, 2026 |
| Order window, expanded disclosure | Nov 2019 – Aug 2021 |
| Countries affected, initial disclosure | US, UK, Sweden, Colombia, Brazil, Italy, Portugal |
| Root vulnerability | CVE-2026-72898, Metabase SQL injection, CVSS 10.0 |
| Data retention policy required by SatoshiLabs | Delete or anonymize after 90 days |
Market Impact: Why This Matters Beyond Trezor Customers
Hardware wallets are sold on a simple promise: keep your keys offline and nobody can touch your crypto remotely. That promise still technically held here, no funds moved, no device was compromised. But the market doesn’t price risk purely on technical compromise, it prices it on trust, and a breach that hands physical addresses to an extortion group tied to ShinyHunters chips away at the “cold storage is safe storage” pitch that hardware wallet makers use to justify a $50-$250 price tag over a free software wallet.
For SatoshiLabs specifically, the bigger cost is likely to be regulatory and contractual rather than immediate revenue. GDPR-covered customers in the UK, Sweden, Italy, and Portugal give European data protection authorities standing to ask pointed questions about why a vendor was still sitting on 2019-2021 order records, and Trezor’s contract language requiring 90-day deletion from ShipMonk is now Exhibit A in any inquiry into whether that requirement was actually enforced.
Why Fulfillment and Logistics Are Crypto’s Weakest Link
Every hardware wallet maker faces the same structural problem: the device has to physically arrive at someone’s home, which means a shipping address, a name, and a phone number have to exist somewhere outside the company’s own tightly controlled infrastructure. Fulfillment companies like ShipMonk serve hundreds of e-commerce clients and were never built with crypto-grade threat models in mind, they were built to ship boxes efficiently at scale. A BI tool like Metabase, useful for spotting shipping delays or inventory issues, becomes a liability the moment it is one SQL injection away from every customer record the company has ever touched.
That mismatch, high-value target data sitting inside commodity logistics infrastructure, is the throughline connecting the 2020 Ledger breach and the 2026 Trezor-ShipMonk breach. Different vendors, different vulnerabilities, same structural gap.
What Affected Trezor Customers Should Do Now
Anyone who ordered a Trezor device between November 2019 and August 2021, or between May and August 2026, should assume their name, email, phone number, and home address are in the hands of people running phishing campaigns. Practical steps: never enter a seed phrase into a website, app, QR code, or phone call, regardless of how official it looks. Treat any unsolicited call, email, or letter referencing a Trezor order as hostile. Verify any communication claiming to be from Trezor by going directly to trezor.io rather than clicking a link or scanning a QR code from the message itself. Consider that a known home address tied to crypto ownership carries physical-security risk, not just digital risk, and adjust accordingly, including being cautious about packages, visitors, or contact referencing the wallet purchase.
What Comes Next: Predictions
- The phishing wave will run for months, not weeks. With roughly 80,689 people now confirmed exposed, expect continued reports of calls, emails, and mailed QR-code scams through the rest of 2026 as the data circulates among opportunistic scammers beyond the original attackers.
- Expect more retroactive disclosures. If ShipMonk failed to purge one multi-year order archive, it is reasonable to expect other historical datasets tied to other ShipMonk clients, not just Trezor, could surface in the coming months.
- Hardware wallet makers will rethink fulfillment contracts. Look for stricter, audited data-retention clauses and possibly a shift toward in-house or crypto-specialized logistics providers rather than general e-commerce fulfillment vendors.
- Regulatory scrutiny will follow the GDPR-covered customers first. UK, Swedish, Italian, and Portuguese authorities have the clearest jurisdictional hook, and a formal inquiry into ShipMonk’s data handling is a realistic next step.
- Competitors will use this as a selling point. Expect Ledger, SafePal, and other wallet makers to highlight their own data-handling practices in marketing, even though several of them have their own breach history to account for.
The Bigger Picture for Crypto Custody Security
The Trezor-ShipMonk story is a reminder that crypto self-custody security is only as strong as its weakest connected system, and the wallet itself is rarely that weak point anymore. Attackers who cannot break a properly used hardware wallet’s offline signing process have simply moved to easier targets: the vendors who know your name, your address, and the fact that you own one. That shift, from attacking cryptography to attacking supply chains and human trust, is the defining security trend of 2026 across far more than just crypto, and the ShipMonk breach is one of the clearer examples of it playing out in real time against a security-conscious audience that should, in theory, know better than to fall for a fake letter with a QR code.
Frequently Asked Questions
Was Trezor itself hacked?
No. SatoshiLabs says its own infrastructure, along with Trezor devices and wallet-recovery data, was not touched. The breach happened at ShipMonk, the third-party fulfillment company that ships Trezor orders.
How many Trezor customers were affected in total?
Roughly 80,689 people combined: 13,689 from the original August 13, 2026 disclosure and about 67,000 additional US customers from an older order archive disclosed on September 4, 2026.
Is my crypto at risk if I own a Trezor?
Not directly from this breach. No seed phrases, private keys, or device data were exposed. The real risk is phishing calls, fake letters, and impersonation attempts that try to trick you into revealing a seed phrase or recovery information separately.
What caused the ShipMonk breach?
Reporting points to a critical SQL injection zero-day, tracked as CVE-2026-72898, in Metabase, the business-intelligence tool ShipMonk used to access its customer and order databases. The flaw carries a maximum CVSS score of 10.0.
Who is behind the attack?
Blockchain security firm Holborn has attributed the intrusion to ShinyHunters, an extortion-focused group active in several major 2026 data-theft incidents.
What should I do if I get a phishing call or letter mentioning Trezor?
Do not respond, click links, or scan QR codes from it. Never enter a seed phrase anywhere outside your physical device. Go directly to trezor.io to verify any claimed communication instead of using contact details provided in the suspicious message.
Did this happen to other hardware wallet makers too?
SafePal disclosed a separate breach around the same period, and Coinkite’s Coldcard wallet suffered an unrelated firmware-level exploit in July 2026. Ledger had its own e-commerce database breach back in 2020. Each incident had a different cause.
Is it safe to keep using my Trezor device?
SatoshiLabs says yes, the device itself and its security functions were not compromised. The precaution needed is around social engineering attempts using the leaked contact data, not the wallet’s cryptographic security.



