Staff

Staff

A Trezor supplier, ShipMonk, suffered a data breach that exposed the identities of nearly 14,000 customers, without touching any private keys. Here’s why the risk hasn’t disappeared - it has only changed nature.

Milan, 19 August 2026 - In recent days Trezor disclosed that ShipMonk, the supplier that stores and ships its hardware wallets, suffered a data breach: the name, shipping address, phone number, email and order number of nearly 14,000 customers were exposed. No private key was touched, and no crypto-asset was moved. But that is precisely the point worth examining: when the keys stay safe yet a person’s identity and home address get out anyway, the risk doesn’t vanish - it transforms. And it’s a risk that concerns anyone who self-custodies crypto-assets, not just Trezor customers.

The Trezor case in brief

ShipMonk notified Trezor of the unauthorised access on 10 August; the public disclosure came on 13 August. The exposure affects 11,742 customers with complete data (name, email, phone, address) and 1,947 with partial data, covering orders delivered between 10 May and 8 August 2026 across seven countries, Italy included. Damage was limited by a data-retention policy that requires the deletion of orders older than ninety days. Trezor has already announced an anonymous delivery option arriving by the end of 2026.

Why an address is worth more than an email

An email on its own is of little value to a scammer. A name, home address and phone number together, however, identify a specific person - one who in recent weeks purchased a device whose sole purpose is to safeguard private keys. The most immediate risk is targeted phishing: messages that are fake but credible because they’re built on real data. The less immediate but more serious risk is physical. Physical coercion of crypto-asset holders - so-called wrench attacks - is growing structurally: the public database maintained by Bitcoin security expert Jameson Lopp records over 260 known cases since 2014, while blockchain security firm CertiK counted 52 incidents in the first half of 2026, against 39 in the same period of 2025. Europe’s share rose from 22% to over 40% of the global total, with France in the lead. In 2026 Lopp flagged several cases of mistaken identity or outdated information: once these lists are out, they don’t update and they don’t expire.

Not an isolated case: the supplier is the weak link

The pattern recurs with regularity. In 2020 Ledger suffered an exposure of customer data through an ecommerce partner; in January 2026 Ledger data was exposed at Global-e. Now ShipMonk for Trezor. In none of these three cases was the manufacturer itself breached, and in none of the three did that protect customers: selling a physical device requires a chain of suppliers, each with attack surfaces independent of the manufacturer.

What to do if this affects you

Anyone who received Trezor’s notification should not move their funds: the keys are not compromised, unlike in July’s Coldcard incident. The right steps are different:

  • treat every urgent request as a warning sign, verifying through the manufacturer’s official channels;
  • never type your wallet backup into a website, for any reason;
  • be wary of physical mail: the attacker knows your home address;
  • assess your own physical exposure and how discreetly you discuss your investments;
  • for future purchases, minimise the data you provide (an email not linked to your real identity, payment in crypto or single-use virtual cards, pickup at collection points).

The limit isn’t the device: it’s the person

‘Not your keys, not your coins’ describes a real risk - that of relying on an untrustworthy custodian - but it conceals another: if your keys are at home, the point of attack becomes you,” says Ferdinando Ametrano, CEO of CheckSig. ”Self-custody carries not only a technical risk but a personal one, which no firmware update can fix. It must always remain possible, but it should be chosen with a clear understanding of what it entails: the people caught up in this breach made no mistake - they simply bought a device and provided their address to receive it.

The role of professional custody

In CheckSig’s professional custody, the geography of risk is different for two structural reasons. The first is the separation between identity and physical infrastructure: anyone who entrusts custody to a regulated intermediary doesn’t receive a device at home, and no courier handles the link between a name, an address and a custody device. The customer’s identity is of course still known to the intermediary, but it is subject to a minimisation and retention regime compliant with GDPR, MiCAR and DORA, with an obligation to report incidents to the supervisory authorities.

The second reason is more relevant in light of this specific case: even knowing a customer’s address, an attacker can obtain nothing if that customer is not in a position to move the funds alone, under duress, on the spot. It is the architecture that renders physical coercion ineffective, not the confidentiality of the address. CheckSig applies this principle in its custody protocol: three authorisation stages with multi-signature across a total of eleven keys, distributed among different parties and locations, with time locks that prevent immediate transfer. The verifiability of the model is what makes it a genuine safeguard: hence the public Proof-of-Reserves, the independent SOC attestations and the insurance coverage.

Share on FacebookShare on WhatsAppInstagramShare on LinkedInShare on X