Skip to content

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders
Original Title: "11,742 Shipping Addresses Leaked Alongside Trezor Orders"
Original Author: KarenZ, Foresight News


A hardware wallet that protects Bitcoin has inadvertently exposed its owner.


On August 11, a Trezor user flaunted the newly received Trezor Safe 3. What surprised him was not the device inside the box, but the shipping label on the box: instead of using a generic product name like "electronic device," it explicitly stated — "Trezor Safe 3 Bitcoin Only."



This means that before the package was delivered, the courier, sorting personnel, and even neighbors who may have seen the package had the opportunity to know that the recipient had purchased a Bitcoin hardware wallet. The poster, Angelus Borgia, noted that this was a domestic shipment in the U.S., not involving international customs declaration, so he questioned, "Why print the full product name on the outside?"


Two days later, on August 13, Trezor disclosed an even more severe message: its logistics partner ShipMonk had experienced a data breach, affecting nearly 14,000 customers' names, emails, phone numbers, and shipping addresses.


It is important to note that these two incidents do not have a confirmed direct causal relationship. The former involved the product name being written on the shipping label, while the latter was due to ShipMonk's system being unlawfully accessed; the post was not a pre-disclosure of the data breach.


However, the timing of these events is still intriguing: two days before Trezor publicly disclosed the data incident, a user had already pointed out that the logistics process was exposing "who purchased a Bitcoin hardware wallet" to unnecessary individuals.


These two different forms reveal the same issue: a hardware wallet can protect the private keys but cannot sever the link between the wallet and the user's real-world identity.


What Was Leaked by 13,689 Affected Customers?


According to Trezor's notification, its logistics partner ShipMonk informed Trezor on August 10 that an unauthorized party had accessed the system storing customer data. Trezor stated on August 13 when publicly disclosing the incident that the investigation was still ongoing.


Trezor currently lists two groups of affected customers totaling 13,689 individuals:


· 11,742 individuals had their name, email, phone number, and full shipping address exposed;


· 1,947 individuals had their name, city, and email exposed, but not detailed shipping addresses.


The disclosure notification mentioned that the exposure of full details mainly involved customers from the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, who received orders handled by ShipMonk between May 10 and August 8, 2026.


Trezor had originally requested both themselves and their logistics partner to delete or anonymize the relevant data 90 days after order completion. However, Trezor later added that among the 1,947 customers whose data was only partially exposed, there may be earlier orders, and the exact time frames are still being verified with ShipMonk.


According to Trezor's current statement, all confirmed affected customers have been individually contacted via help@trezor.io; those who have not received a notification email are not within the scope of this confirmation.


Trezor also emphasized that their own systems, products, and services were not compromised, and hardware wallets, private keys, and wallet backups were not part of this leak. In other words, this was not attackers breaching Trezor devices to directly siphon assets but a customer data exposure in a third-party logistics system.


This distinction is crucial, but "device not compromised" does not equate to "no security risk for the users."


The Leak Was Not of Private Keys but of "Who Might Hold Cryptocurrency Assets"


Names, phones, and addresses alone cannot unlock a cryptocurrency wallet; owning a hardware wallet also does not prove that someone still holds cryptocurrency assets, let alone the scale of their holdings.


The real issue is that this information has been tagged with a specific label: this person has purchased a hardware wallet.


For scammers, accurate names, device brand, order details, and home addresses significantly enhance the credibility of a scam. Attackers can impersonate Trezor, exchanges, banks, or logistics companies, accurately stating the recipient's real information and then persuading them to scan a QR code, install malware, or submit a recovery seed under pretexts like "security upgrade," "device recall," "wallet migration," or "account verification."


Furthermore, the attack vectors are not limited to email.


In February 2026, security outlet BleepingComputer reported that individuals were sending counterfeit official letters to Trezor and Ledger users, asking recipients to scan a QR code to complete a supposed "identity verification" or "transaction check." The QR codes ultimately led to fake wallet websites, prompting users to enter their recovery phrases.


The report did not confirm which data breach these shipping addresses specifically came from. However, it does demonstrate that once a home address is associated with a hardware wallet user's identity, attackers can indeed move phishing emails from the inbox to the real world.


As a result, Casa co-founder Nick Neuman warned that this address leak could increase targeted social engineering and even real-world coercion risks. Bitcoin network security expert and author of "Defending Bitcoin," Luke de Wolf, emphasized that the breach occurred at Trezor's service provider, not the Trezor device itself, while suggesting that users consider using a PO Box or other non-residential address when purchasing Bitcoin-related products.


These warnings serve as risk assessments and do not imply that every customer will fall victim to scams or physical threats. However, if an attacker has access to a person's name, phone number, address, and device information simultaneously, the affected party should clearly no longer treat the communication as just another spam email.


The logistics label controversy on August 11 is also part of this issue. While a database breach requires attackers to first infiltrate a system, openly labeling the outer box as "Bitcoin Only" actively exposes the content to more people during normal package transit. The former is a security incident, and the latter is a lack of data minimization awareness; although the risks vary, both contribute to expanding unnecessary awareness.


Multiple Incidents with Hardware Wallets, but the Risks Differ


Around this leak, the discussion quickly shifted beyond Trezor itself, evolving into a larger question: Are hardware wallets still trustworthy?


Noteworthy is ZachXBT's statement on July 16 in a Telegram chat, where he advised against using a hardware wallet to store significant funds and proposed owning a dedicated iPhone instead. This reflects ZachXBT's personal security solution preference.


Compared to ZachXBT's outright rejection of hardware wallets, Zhao Changpeng's stance is more moderate. On August 13, he commented on the Trezor incident, stating that hardware wallets are generally more secure in some aspects than software wallets. However, these two types have different risk structures: self-hosted software wallets do not require the purchase and transportation of a physical device, thus avoiding linking a user's identity, home address, and hardware wallet purchase history during distribution.


Zhao Changpeng also emphasized it is not about deeming hardware wallets as "bad" but rather about helping users understand the trade-offs between security, privacy, and convenience. It is worth noting that purchasing a hardware wallet does not prove that one still holds cryptocurrency assets. However, such records may identify the person as a potential holder, thereby increasing phishing, social engineering, and real-world security risks.


However, regardless of which viewpoint one agrees with, judging the security of a hardware wallet should not lump all events together. While Trezor, COLDCARD, and Ledger have all been thrown into the same "hardware wallet security event" basket, the actual vulnerabilities and consequences are not the same.


The recent COLDCARD incident belongs to a different type of risk.


On July 30, hardware wallet manufacturer Coinkite, the maker of Coldcard, issued a security advisory warning that wallets generated with a specific firmware version of COLDCARD Mk3 may be at risk. The affected range starts from version 4.0.1 released in March 2021 and extends up to the last supported Mk3 version, 5.0.3. According to Coinkite's initial analysis, Mk4, Q, and Mk5 are not affected. This is an issue related to the device's key generation process, fundamentally different from Trezor's recent logistics data leak.


As of August 7, according to Galaxy Research, based on victim reports, it is now highly believed that approximately 1,719 bitcoins (worth around $111 million) were stolen due to a Coldcard hardware wallet vulnerability, with more suspicious funds still being verified, and the total expected loss could exceed $130 million.


The Global-e incident involving Ledger in January 2026 is more similar to Trezor's. The attack targeted Ledger's third-party e-commerce partner, exposing data including customer names, contact information, and order details; Ledger stated at the time that its hardware and software systems were not affected, and payment data, passwords, and recovery phrases were not compromised.


Therefore, at least three types of issues need to be distinguished:


One is device or firmware vulnerabilities that could affect key generation, storage, or transaction signing; two is database leaks from manufacturers and their service providers that could expose customer identities and order information; and three is overexposure in the logistics, packaging, and customer service processes, allowing sensitive information to be accessed by individuals who do not need to know.


What Should Affected Parties Do Now?


First, just because a contact knows your real name, address, phone number, order information, or even device model, do not automatically trust that they are from Trezor. Now is the time to reverse that understanding: the more specific information someone knows, the more likely they are leveraging leaked data to increase the credibility of a scam.


Do not click on unfamiliar links in security notifications or scan QR codes from unknown sources. When checking for updates on an event, manually enter the Trezor official domain or access it from a verified official account. Hardware wallets, exchanges, and so-called "security researchers" will never ask for your wallet's seed phrase to verify your identity.


For users whose home address has been exposed, it is advisable to minimize the disclosure of asset balances, residential locations, travel plans, personal photos, and other information on social media. If you receive explicit threats, extortion demands, or suspicious visits, preserve evidence and contact local law enforcement instead of engaging with the individuals directly.


When purchasing a hardware wallet or other sensitive security products in the future, consider using an email address that is separate from your everyday identity. Where local conditions and laws permit, utilize lockers, PO boxes, or alternative non-residential addresses to reduce the direct association between your address and the purchased product.


Trezor has announced that they are developing an "Anonymous Shipping" service, which will feature a dedicated checkout process, locker pickup options, neutral packaging, anonymous sender information, and automatic deletion of relevant identifiers after delivery. The service is set to launch in the EU in September 2026 and expand to the United States by the end of the year.


Security Begins Long Before the Hardware Wallet Boots Up


This incident underscores a fundamental principle: security should not commence only when a user boots up a device for the first time.


When a package prominently displays "Bitcoin Only" on the outside, and when logistics databases can link names, phone numbers, and home addresses to hardware wallet orders, even if the device's internal private keys remain undisclosed, the user's security perimeter has already been breached.


For a company that sells financial self-sovereignty tools, minimizing data collection, retention, and restricting knowledge of who purchased what should also be integral to product security.


Original Article Link


Recommended

Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Aug 14, 18:37
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps

Tether Receives Fourth Audit, but Transparency Concerns Regarding USDT Remain Unresolved

Aug 14, 17:00
Tether Receives Fourth Audit, but Transparency Concerns Regarding USDT Remain Unresolved

Sandi's Buyback Arithmetic: 2030 EPS to See $787

Aug 14, 16:32
Sandi's Buyback Arithmetic: 2030 EPS to See $787

Hong Kong Dollar Stablecoin 'Great Exodus'

Aug 14, 14:27
Hong Kong Dollar Stablecoin 'Great Exodus'

BofA Analysis: Micron's $100 Billion Cash Flow, Can It Navigate the NAND Cycle?

Aug 14, 13:17
BofA Analysis: Micron's $100 Billion Cash Flow, Can It Navigate the NAND Cycle?

X Publicizes Full Recommendation Algorithm, How to Write Posts for High Exposure

Aug 14, 13:14
X Publicizes Full Recommendation Algorithm, How to Write Posts for High Exposure