Trezor says a breach at shipping partner ShipMonk exposed personal order data for about 13,689 customers. The hardware wallets were not hacked. The live risk is targeted phishing against people whose names, phones, emails, and in most cases shipping addresses sat in a logistics system, not a firmware drain of seed phrases.
That is a self-custody plumbing story, not a Bitcoin range story. CoinGecko’s desk snapshot at 2026-08-14T00:15:13+00:00 still has Bitcoin at $63,448, up 0.1% over 24 hours, with a market cap near $1.27 trillion. The tape is quiet. The leak is not.
I am treating this as logistics PII, full stop, until a company primary says otherwise.
What happened
On Monday, August 10, 2026, ShipMonk told Trezor that an unauthorized actor had reached systems holding customer data. Trezor’s team published the notice on August 13. The company blog is the lead document. CoinDesk later summarized the same disclosure for a wider audience.
Trezor splits the affected set in two. Full exposure covers 11,742 customers: name, email, phone number, and shipping address. Partial exposure covers 1,947 customers: name, city, and email, without the street address. Add those and you get the 13,689 working total. Order numbers were also among the fields ShipMonk holds to move a parcel.
The window Trezor names for new customers is orders received in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and August 8, 2026. ShipMonk is described as the logistics partner that stores product and ships into those lanes. Trezor says its own systems, products, and services were not compromised, and that devices remain secure.
Trezor also says this is the first time since it was founded in 2013 that a breach exposed customer phone numbers and shipping addresses. That sentence matters. Email dumps are common. A home address plus a phone next to a known hardware-wallet order is a different phishing kit.
Affected buyers were contacted from help at trezor.io. Trezor says that if you did not get that mail, you are not in this incident set. An update on the same page flags a live uncertainty: the 1,947 partial-exposure records may include older orders, and Trezor is still checking the timeframe with ShipMonk. Do not treat the 90-day fence as fully closed until that update lands.
Context
Self-custody is supposed to shrink counterparty risk. It does that for keys. It does not delete the fact that a physical device still has to travel through a warehouse, a 3PL, and a last-mile carrier. Those firms need a name, a phone, and a door. Trezor says it negotiated a 90-day delete-or-anonymize rule with fulfillment partners, matching its own shop policy, because delivery, returns, and replacements still need a window. That policy is why the company argues older orders were not sitting in ShipMonk systems. The partial-exposure caveat is the hole in that argument today.
The phishing path is obvious. A scammer who knows you bought a Trezor, and where it was shipped, can fake a support mail, a courier call, or a paper letter. The ask will be the same one every wallet guide warns about: type your seed phrase into a “migration” page, or photograph the backup “for verification.” Trezor repeats the hard rule. Never enter a wallet backup on a website. Never share it with anyone.
This is a different failure mode from the Coldcard weak-seed episode we already covered. That case was about entropy inside a device. This case is about who holds the shipping list. Both sit under self-custody. They are not the same bug. A cold wallet can still be perfect at holding keys and terrible at hiding that you bought one.
Bitcoin itself did not reprice the news. Coinbase’s BTC-USD 24-hour stats at about 00:25 UTC on August 14 showed a last trade near $63,471, a session high of $63,949.90, a low of $62,772.84, and about 4,960 BTC of venue volume. The top of Coinbase’s book at 2026-08-14T00:26:51Z was $63,420.39 bid versus $63,420.40 ask, with only about 0.026 BTC on the bid touch and about 0.61 BTC on the ask touch. That is a quiet spot tape, not a panic print. ETF flow tables were not reachable from this run (Farside returned a bot challenge), so I am not inventing a flow number to dress the range.
Trezor also sketches a future “Anonymous Delivery” option: dedicated checkout, locker pickup, neutral packaging, generic sender details, and deletion of shipping identifiers after delivery. The stated aim is the EU by September 2026 and the United States by year-end. That is a product target, not a live control. I will not score it until a checkout page exists.
If you want the operational checklist rather than the market read, our wallet safety guide is the companion. The Bitcoin history page is the longer cycle context for why people keep buying these devices even when the price sits in a tight band. Latest desk notes on the asset live under Bitcoin News.
Our read
Stance: this is a logistics-PII event with a phishing tail, not a Trezor firmware or seed-generation event. The 13,689 figure is large enough to matter for social engineering and small enough, relative to years of hardware-wallet sales, that the Bitcoin tape can ignore it. Ignoring it as a holder is a mistake if you are in the notified set.
The structural point is harsher. Every hardware-wallet maker that ships a brick is also in the parcel business. Encryption on the device does not encrypt the packing slip. A 90-day retention rule is a real control. It is also an admission that for three months your identity and your device purchase sit together at a vendor you did not choose. That is counterparty risk with a different label.
Falsifiable claim: by 2026-09-30 23:59 UTC, if Trezor or ShipMonk publishes a primary update showing that Trezor.com accounts, device firmware, or seed-related systems were accessed in this same incident, this logistics-only read is wrong. A numbered Trezor blog post that only revises the 1,947 older-order count, without touching device systems, would not kill the claim. It would just move the PII total.
What to watch next
First, the 1,947 caveat. Watch for Trezor to confirm or retract the idea that partial exposure includes orders older than the 90-day window. A higher total, or a longer lookback, changes how many people should assume they are in the phishing set even without a help at trezor.io mail.
Second, the phishing wave, not the price. A quiet Coinbase book next to a fresh address dump is the dangerous mix. Seed-extraction mails will mention the model you bought and the street you used. If Trezor later documents a confirmed theft that started from this list, that is the incident’s second chapter.
Third, whether Anonymous Delivery actually ships in the EU in September 2026 as aimed. A blog promise is not a locker network. If the option is late or US-only, the 3PL PII problem stays the default.
Fourth, copycats. One named 3PL incident will pull attention to every other hardware vendor’s fulfillment stack. I will wait for those companies’ own blogs or regulator notices. Outlet roundups are not a second event.