Marcus bought a Trezor in 2020 and has not thought about the order since. Last week an email arrived, addressed to him by name, quoting his order number, saying his device firmware had a fault and he should confirm his wallet backup on a linked page to keep his coins safe. Everything in it was accurate except the sender. His name, email address, phone number, home address and that order number were in a file taken from Trezor’s shipping provider, and the person holding it needed only one more thing from him: the 24 words.
Confirmation: confirmed by the company. Trezor published a notice on 13 August 2026 and updated it on 4 September 2026 with the larger count.
What happened
On 4 September 2026, Trezor said the breach at its shipping provider ShipMonk was far larger than first reported, and that ShipMonk had held customer data it had confirmed in writing was deleted. The timeline is in Trezor’s own notice.
ShipMonk, the logistics company that stores Trezor’s products and ships orders in the US, UK and several other countries, told Trezor on 10 August that an unauthorised party had accessed systems holding customer data. Trezor’s first notice on 13 August put the impact at 11,742 customers with full exposure and 1,947 with partial exposure, covering orders delivered between 10 May and 8 August 2026 to customers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
On 2 September, Trezor says, it learned the stolen data also included orders from an earlier period of the relationship, November 2019 to August 2021. Trezor’s policy is to delete or anonymise order data 90 days after delivery, and it says it had asked for and received written confirmation from ShipMonk that this older data was gone. It was not. That added roughly 67,000 US customers, bringing the total to 80,689.
Trezor says its own systems were not breached, that no device, private key or wallet backup was affected, and that every affected customer has been emailed directly from its official address. If you did not get that email, the company says, you are not affected.
BleepingComputer reported that breach notification emails describe the way in as a vulnerability in Metabase, a third-party analytics tool, the same flaw used against Mathspace, Framework and Tally in recent weeks, and that ShipMonk has received extortion emails from the ShinyHunters group. Trezor itself has not said how ShipMonk was breached.
This is not the first time. In January 2024, a breach at Trezor’s third-party support portal exposed names and email addresses of about 66,000 users, and that data was later used in phishing campaigns asking for wallet recovery seeds.
What was exposed
For most of the 80,689 people, the file holds full name, email address, phone number, shipping address and order number. For 1,947 of them the exposure was limited to name, city and email address. The contents of the parcel were not included, but the sender was Trezor, so the contents are not a mystery.
What each item is worth to a criminal:
- Your email address, paired with the fact that you own a hardware wallet. That is the whole value of this file. A generic crypto phish is easy to ignore. One that arrives from “Trezor,” names you correctly and quotes your real order number is not.
- Your phone number. A follow-up call or text from “Trezor support” about a firmware problem, or a text carrying a link to a fake Trezor Suite login. The 2024 breach produced exactly these.
- Your home address. Trezor’s own notice raises the physical risk plainly: a letter dressed as a recall notice, or, for a large enough holding, someone at the door.
- Your order number and date. Small details that make a fake message read as internal. “Regarding order #TR-xxxxx” is the line that gets the email opened.
No password leaked here, because ShipMonk did not hold one. No seed phrase leaked, because Trezor does not hold yours. The attack that follows is designed to get you to hand the seed over yourself.
What to do now
The risk is not that someone can take your coins with this data. It is that someone will use it to talk you into giving them the one thing that can. Most of what protects you has nothing to do with OptMsg.
1. Do not type your recovery seed into anything. Not a website, not an app, not a form sent by “Trezor.” Trezor’s notice says it in bold and it is the whole game: the device asks for the seed on its own screen during recovery, and nowhere else. 2. Treat every message about Trezor, your order, firmware, or this breach as suspect, including the ones that look right. Do not follow links in them. Open trezor.io or Trezor Suite yourself. Trezor says to cross-check anything you receive against its blog and official social channels. 3. Expect the phone to ring. Your number is in the file. Trezor does not call customers about firmware or security incidents. Hang up and check the website. 4. Turn on the strongest sign-in every account tied to that email address offers, starting with the email account itself, because it is the reset route into your exchange accounts and everything else. A passkey where available, an authenticator app otherwise. A password manager makes unique passwords painless. 5. If your home address and a large holding both worry you, Trezor’s advice on its notice covers ordering more privately in future. For now, consider a passphrase-protected hidden wallet so that the seed alone does not open everything. 6. Watch for password-reset emails you did not request on any account using the exposed address. That is someone trying the door. 7. If you already clicked or typed anything, move funds to a new wallet with a fresh seed now, from a device you trust, and then work out what happened.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this breach. It happened at ShipMonk, in ShipMonk’s systems, holding data Trezor had been told was deleted. What an opt-in inbox changes is what happens to you afterwards.
Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the fake “confirm your wallet backup” email lands in Trash, where you are not reading it under time pressure; Trezor reaches your Inbox only if you approved it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash. A criminal who spoofs an address you did approve is a different problem, and one the steps above cover.
Then the password point. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. When someone takes an email address from this file and pairs it with a password from some other breach, the pair opens nothing at OptMsg — there is no password on the account to match. That matters here because the inbox is where exchange and wallet-software resets land.
What that does not cover: a text or a phone call to your number, a phishing page you open yourself, an exchange account with its own password, or someone with your unlocked phone. Those are the steps above.
If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read what opt-in email is and how it shields your inbox.
Ready for an inbox that stays quiet after a breach? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
Are my coins at risk from the Trezor data breach? Not from the leaked data itself. Trezor says its systems, devices, private keys and wallet backups were not affected. The risk is a phishing email, call or letter that uses your name, order number and address to persuade you to enter your recovery seed somewhere. Do not.
How do I know if I am affected? Trezor says every affected customer was emailed directly from its official address, and that if you did not receive that email you are not affected. Check that the sender domain is trezor.io, and do not follow links in it; go to trezor.io yourself.
I ordered years ago. Why is my data in this? Trezor’s policy deletes order data 90 days after delivery and it says ShipMonk confirmed in writing that data from November 2019 to August 2021 had been deleted. On 2 September Trezor learned it had not been. That is where the extra 67,000 US customers come from.
Should I move my coins to a new wallet? Only if you have already entered your seed somewhere you should not have, or you have reason to think it is exposed. In that case, move funds to a new wallet with a fresh seed from a device you trust. Otherwise the seed is not part of this breach.
Would OptMsg have stopped this? No. The breach happened at ShipMonk. What OptMsg changes is the aftermath: unapproved senders go to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.
Sources
- Trezor — Recent customer data exposed in shipping provider incident, 13 August 2026 (updated 4 September 2026)
- BleepingComputer — Trezor data breach impact now reaches 81,000 customers, 7 September 2026
- BleepingComputer — Trezor discloses data breach affecting nearly 14,000 customers, August 2026
- BleepingComputer — Trezor support site breach exposes personal data of 66,000 customers, January 2024