Original Title: "11,742 Shipping Addresses Leaked Alongside Trezor Orders"
Original Author: KarenZ, Foresight News
A hardware wallet protecting Bitcoin has inadvertently exposed its owner.
On August 11, a Trezor user shared their newly received Trezor Safe 3. What surprised them was not the device inside the box, but the shipping label on the box: instead of using a vague product name like "electronic device," it explicitly stated — "Trezor Safe 3 Bitcoin Only."

This meant that before the package was delivered, the courier, handlers, and possibly neighbors who saw the package had the opportunity to know that the recipient had purchased a Bitcoin hardware wallet. The poster, Angelus Borgia, noted that this was a domestic U.S. shipment without involving international customs clearance, raising the question: "Why must the full product name be printed on the outside?"
Two days later, on August 13, Trezor made a more severe disclosure: their logistics partner, ShipMonk, had experienced a data breach, affecting nearly 14,000 customers' names, emails, phone numbers, and shipping addresses.
It is important to note that these two incidents do not have a confirmed direct causal relationship. The former involved the product name being printed on the shipping label, while the latter was due to an unauthorized access to ShipMonk's system. The post was also not an early disclosure of the data breach.
However, the timing of these events is still thought-provoking: two days before Trezor publicly disclosed the data incident, a user had already pointed out that the logistics process was exposing "who purchased a Bitcoin hardware wallet" to unnecessary individuals.
While the forms of these incidents differ, they both reveal the same issue: a hardware wallet can protect the private key but cannot independently sever the link between the wallet and the user's real-world identity.
According to Trezor's notification, their logistics partner, ShipMonk, informed Trezor on August 10 that unauthorized individuals had accessed the system holding customer data. When Trezor publicly disclosed the event on August 13, they stated that the investigation was ongoing.
Trezor currently lists two groups of affected customers totaling 13,689 individuals:
· Exposed information of 11,742 individuals includes names, email addresses, phone numbers, and complete shipping addresses;
· 1,947 individuals had their names, city of residence, and email addresses exposed, but not their detailed shipping addresses.
The disclosure notification stated that the exposure of full information mainly involved customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, who received orders processed by ShipMonk between May 10 and August 8, 2026.
Trezor originally requested that both itself and its logistics partner delete or anonymize the relevant data 90 days after order fulfillment. However, Trezor later added that among the aforementioned 1,947 customers with only partial data exposed, there may be earlier orders that are still being verified with ShipMonk to determine the exact timeframe.
According to Trezor's latest statement, all affected customers have been individually contacted via help@trezor.io; those who have not received a notification email are not within the scope of this confirmation.
Trezor also emphasized that its internal systems, products, and services were not compromised, and hardware wallets, private keys, and wallet backups were not part of this leak. In other words, this incident did not involve attackers breaching Trezor devices to directly siphon off assets; instead, it was a customer data leak from a third-party logistics system.
This distinction is crucial, but "no device compromise" does not equate to "no security risk for users."
Names, phone numbers, and addresses alone cannot unlock a cryptocurrency wallet. Merely owning a hardware wallet does not prove that someone still holds cryptocurrency, let alone indicate the scale of their holdings.
The real issue is that this information has been tagged with one specific label: this person has purchased a hardware wallet.
For scammers, having accurate names, device brands, order details, and home addresses can significantly enhance the credibility of scams. Attackers can impersonate Trezor, exchanges, banks, or logistics companies, providing recipients' real information and then persuading them to scan QR codes, install malware, or submit mnemonic phrases under the guise of "security upgrades," "device recalls," "wallet migrations," or "account verifications."
Furthermore, the attack vectors are not limited to email.
In February 2026, the cybersecurity outlet BleepingComputer reported that individuals were mailing counterfeit official letters to Trezor and Ledger users, asking recipients to scan QR codes to complete supposed "identity verification" or "transaction checks." The QR codes ultimately directed users to fake wallet websites and prompted them to enter their recovery phrases.
The report did not confirm which data breach these shipping addresses specifically came from. However, it does demonstrate that once a residential address is linked to a hardware wallet user's identity, attackers can indeed move phishing emails from the inbox to the physical world.
As a result, Casa Co-founder Nick Neuman warned that this address leak could increase targeted social engineering and even real-world coercion risks. Bitcoin network security expert and author of "Defending Bitcoin," Luke de Wolf, emphasized that the breach occurred at Trezor's service provider, not the Trezor device itself, and advised users to consider using a post office box or other non-residential address when purchasing Bitcoin-related products.
These warnings are risk assessments and do not imply that every customer will encounter fraud or physical threats. However, if an attacker holds a victim's name, phone number, address, and device information simultaneously, the affected party should clearly not treat the incoming mail as ordinary spam.
The August 11th logistics label dispute also falls under this issue. A database breach requires attackers to first penetrate the system. On the other hand, labeling the outer box directly with "Bitcoin Only" actively exposes the contents to more people as the package circulates normally. The former is a security incident, the latter is a lack of data minimization awareness; the severity of the risks may differ, but both contribute to enlarging an unnecessary circle of knowledge.
Around this leak, the discussion quickly expanded beyond Trezor itself, evolving into a larger question: Are hardware wallets still trustworthy?
It is worth noting that ZachXBT stated on Telegram on July 16th that he does not recommend using a hardware wallet to store significant funds and believes having a dedicated iPhone is a better option. This reflects ZachXBT's personal security solution assessment.
Compared to ZachXBT's complete rejection of hardware wallets, Zhao Changpeng's statement is more restrained. On August 13th, when commenting on the Trezor incident, he expressed that hardware wallets are generally still more secure in some aspects than software wallets, but they have different risk structures: software self-custody wallets do not require the purchase and transportation of physical devices, thus do not link a user's identity, residential address, and hardware wallet purchase record in the distribution process.
Zhao Changpeng also stressed that it is not about considering hardware wallets as "bad," but rather about users understanding the trade-offs between security, privacy, and convenience. It should be noted that buying a hardware wallet does not prove that one still holds cryptocurrency assets, but such records may depict them as potential holders, thereby increasing phishing, social engineering, and real-world security risks.
However, regardless of which view you subscribe to, assessing the security of a hardware wallet should not lump all incidents together. While Trezor, COLDCARD, and Ledger have all been placed in the "hardware wallet security incident" basket, the actual vulnerabilities and consequences are not the same.
The recent COLDCARD incident falls into another category of risk.
On July 30, the Coldcard hardware wallet manufacturer Coinkite released a security advisory warning that wallets generated with a specific firmware version of COLDCARD Mk3 may be at risk. The affected range spans from version 4.0.1 released in March 2021 to the final supported version of Mk3, 5.0.3. According to Coinkite's preliminary analysis at the time, Mk4, Q, and Mk5 are unaffected. This issue is related to the device's key generation process and is fundamentally different from the Trezor logistics data leak.
As of August 7, according to Galaxy Research, based on victim reports, it is now highly believed that approximately 1,719 bitcoins (worth about $111 million) have been stolen due to the Coldcard hardware wallet vulnerability, with more suspicious funds still being verified, and the total loss is estimated to exceed $130 million.
The Global-e event that occurred in January 2026 involving Ledger is more akin to Trezor. The attack targeted Ledger's third-party e-commerce partner, exposing data including customer names, contact information, and order details; Ledger stated at the time that its hardware and software systems were not compromised, and payment data, passwords, and recovery phrases were not disclosed.
Therefore, at least three types of issues need to be distinguished:
One is device or firmware flaws that may affect key generation, storage, or transaction signing; two is database leaks from manufacturers and their service providers, which may expose customer identities and order information; three is overexposure in logistics, packaging, and customer service processes, allowing unnecessary exposure of sensitive information to people who should not have access to it.
Firstly, do not trust someone claiming to be from Trezor just because they know your real name, address, phone number, order information, or even device model. Now is the time to reverse that understanding: the more detailed information the other party knows, the more likely they are leveraging leaked data to enhance the credibility of a scam.
Do not click on unfamiliar links in security notifications, and do not scan QR codes from unknown sources. When you need to check for updates on an event, manually enter the Trezor official domain or access it from a confirmed official account. Hardware wallets, exchanges, and so-called "security researchers" will never ask for your wallet seed phrase to verify your identity.
For users whose home addresses have been exposed, avoid disclosing your asset balances, residential location, travel plans, personal photos, and other information on social media. If you receive explicit threats, ransom demands, or suspicious visits, keep evidence and contact local law enforcement instead of engaging with the other party directly.
In the future, when purchasing a hardware wallet or other sensitive security products, consider using an email address separate from your everyday identity. Where local conditions and laws permit, utilize pickup lockers, PO boxes, or other non-residential addresses to reduce the direct association between your address and the product.
Trezor has announced that they are developing an "Anonymous Delivery" service, which will involve a dedicated checkout process, pickup lockers, neutral packaging, anonymous sender information, and automatic deletion of relevant identifiers after delivery. The service is set to launch in the European Union in September 2026 and expand to the United States by the end of the year.
This incident truly underscores that security should not start only when a user powers on a device for the first time.
When a package prominently displays "Bitcoin Only" on its exterior, and when the logistics database can link a name, phone number, and home address to a hardware wallet order, even if the device's private keys have never been exposed, the user's security perimeter has already been breached.
For a company selling financial sovereignty tools, minimizing data collection, retention, and limiting who knows what a person has purchased should also be part of product security.
Original Article Link
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia