Thirteen thousand six hundred eighty-nine people ordered a hardware wallet from Trezor this year and ended up with their home address in a stranger’s hands instead. That’s the real number behind one of the messier crypto security stories of August, and it didn’t come from anything inside Trezor’s own walls.

The Trezor data breach traces back to ShipMonk, the third-party logistics firm that packs and ships Trezor hardware wallets to buyers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor confirmed the incident in a blog post published Thursday, and the split is ugly. 11,742 customers had their full name, email, phone number, and shipping address exposed. Another 1,947 saw a smaller leak, just name, city, and email.

Orders placed between May 10th and August 8th, 2026 sit inside the exposed window. Anything older had already been deleted under Trezor’s own 90-day retention policy, which is the only reason the number isn’t much bigger.

A Home Address Tied To A Hardware Wallet

Trezor broke the news itself first, in a long post on X that opened with “we have some difficult news to share.” Trezor’s wording stayed careful throughout the thread. Systems weren’t touched, the company said, no seed phrase or private key left ShipMonk’s servers, and devices remain safe to use.

Trezor breach announcement on X
Trezor — breach announcement thread on X, 5.3 million views, screenshotted August 14, 2026.

What actually leaked was the boring stuff. A name. A phone number. A street address. That’s exactly the problem, according to several replies under the post. A stolen recovery seed is close to useless without physical access to the matching device. A leaked address already confirmed to belong to a hardware wallet owner is a different kind of risk. X user King Arthi put it bluntly: “that’s not a normal data leak, that’s a targeting list for the wrench,” a nod to the old webcomic about beating a password out of someone with five dollars of hardware store tools. Not every reply bought Trezor’s version of events either. One user guessed the data was sold by an insider rather than stolen, though nothing public backs that theory up.

CZ Turns The Breach Into A Pitch

Binance co-founder Changpeng Zhao weighed in a few hours later, and his post read less like sympathy and more like an ad. “Not a great month for hardware wallets,” CZ wrote, walking through the same 13,689-customer figure before arguing the incident “reinforces an advantage” of software wallets such as Binance’s own Web3 Wallet and Trust Wallet, since neither one requires shipping a physical device to a real address.

CZ Binance reaction to Trezor breach on X
CZ Binance — reaction post on X, 324,600 views, screenshotted August 14, 2026.

CZ did add a disclaimer of his own. He isn’t calling hardware wallets bad, just “different risk profiles,” and he disclosed that YZiLabs, his venture arm, is an investor in several hardware wallet makers. Still, the framing landed the way most CZ posts do lately. A security incident becomes a two-minute case for the products his own companies sell.

How ShipMonk Actually Got Hit

Trezor never said how ShipMonk’s systems were breached. BleepingComputer filled that gap after reviewing the actual breach notification emails ShipMonk sent to affected customers. The culprit was Metabase, a third-party analytics tool ShipMonk uses internally, not anything Trezor or ShipMonk built themselves.

BleepingComputer report on Metabase zero-day attacks
BleepingComputer — report on the Metabase zero-day behind the ShipMonk breach, screenshotted August 14, 2026.

“On August 6, 2026, Metabase informed us that an unauthorized party exploited a vulnerability in Metabase’s software,” ShipMonk told its own customers, per the emails BleepingComputer reviewed. The bug was a critical SQL injection zero-day letting attackers grab administrator access to any exposed Metabase instance, and ShipMonk wasn’t the only victim. Laptop maker Framework and form-builder Tally both got hit through the same hole. Worse, ShipMonk has reportedly since received extortion emails from ShinyHunters, a group with a long track record of monetizing exactly this kind of stolen customer data.

Trezor’s Rough Two Weeks

CZ’s “not a great month” line undersells it a little. Eight days before the ShipMonk news broke, Trezor was already fielding panicked questions over a separate scare, a wallet-generation vulnerability disclosed by rival Coldcard on July 30th that didn’t actually touch Trezor devices at all. And this isn’t even Trezor’s first customer-data incident. Back in January 2024, a breach of its support ticketing portal exposed roughly 66,000 users‘ names and emails, and attackers used that batch of data to run phishing campaigns aimed straight at recovery seeds.

Trezor official blog post on the ShipMonk data breach
Trezor — official blog post detailing the breach and FAQ, screenshotted August 14, 2026.

Trezor says this is still the first time in company history that a breach has reached as far as phone numbers and home addresses. It’s now promising an “Anonymous Delivery” option, locker pickup, generic sender labels, no name tied to the parcel, aimed at Europe by September and the US by year end. Until then, the company’s own advice to customers stands. Never type a recovery seed into a website, and treat any unexpected email or call about the breach as a phishing attempt until proven otherwise.