Trezor Data Breach 2026: What UK Crypto Owners Should Do Now

By Simon Bumford, Founder · · 22 min read

Trezor was not hacked, but a shipping partner leaked names and home addresses, growing to around 80,000 people in September. What UK owners should do now.

The short version

Last updated: 7 September 2026. This article was first published on 18 August 2026 and has been substantially revised following Trezor's update of 4 September 2026, which roughly sextupled the number of customers affected. On 13 August 2026 Trezor confirmed that one of its shipping partners, a fulfilment company called ShipMonk, had been breached, exposing the order records of 13,689 customers, including customers in the UK. On 4 September Trezor disclosed that the breach was far larger than ShipMonk had first stated: a further 67,000 or so US customers from orders placed between November 2019 and August 2021 were also exposed, from data ShipMonk had confirmed in writing was deleted. Here is what did not happen: your wallet was not hacked. No Trezor system, device, private key or wallet backup was touched, because none of those things ever pass through a shipping database. Your coins are exactly as safe as they were in July. What has changed is who knows about you. A stranger may now know your name, where you live, your phone number, and that you bought a hardware wallet, which is a strong signal that you own cryptocurrency. That invites a predictable follow-up: convincing phishing, fake letters, bogus support calls and, rarely, worse. This article explains what happened, whether you are affected, what the September expansion means for UK customers, the steps that make the leaked data close to worthless, and a longer question the incident raises: how to make crypto discoverable by your family without making yourself a target.

September 2026 update: the breach is about six times larger than first disclosed

On 2 September 2026 ShipMonk told Trezor that the stolen data was larger than previously stated. Trezor published the update on 4 September and posted the same wording on its official X account. The key passage, in Trezor's own words: "It also contained order data from our prior cooperation between November 2019 and August 2021. Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." The newly exposed group is "another approximately 67,000 US customers", with full exposure: name, email address, phone number, shipping address and order number. Trezor has not published a combined total. The figure of roughly 80,700 that appears in some coverage is media arithmetic, adding the August and September numbers together, as Unchained noted when it reported the update. Treat it as an estimate, not a Trezor statement. Two things about this update matter for a UK reader. First, Trezor describes the historic dataset as US customers only. It has not said that any UK orders from 2019 to 2021 were in it, and UK customers who ordered in that period have not been told they are affected. Second, the update directly contradicts what Trezor's original August disclosure said about retention, which is still on the same page: that only orders from the previous 90 days could be exposed "as older data had already been deleted", and that ShipMonk followed the same 90-day policy. Trezor's standing privacy page still states that delivery data "is deleted from our and the fulfillment partner's systems" after 90 days. Trezor has not published the deletion assurances or their dates, and ShipMonk has made no public statement at all as of 7 September. The lesson for any customer who trusts a retention policy is that a written promise to delete data is only as good as the audit behind it, which is a reason to use the data protection rights in the checklist below rather than assume a policy was followed.

Was Trezor actually hacked?

No. Trezor's own systems, products and services were not breached, and Trezor devices were not compromised. The intrusion happened at ShipMonk, a third-party logistics company that stores Trezor products and posts orders to customers in the United States, the United Kingdom and several other countries. What the attackers took was ShipMonk's delivery records: who ordered, where it was sent, and how to contact them. The distinction is not a technicality. A Trezor device generates and holds your private keys offline. Your wallet backup (the recovery phrase) is created on the device and, if handled correctly, exists only in your own physical storage. Neither ever touches a shipping system, so neither could be in the stolen data. Trezor states plainly that "our systems were not compromised, and your Trezor device is secure". Every reputable report of the incident says the same. If you arrived here after searching for "Trezor hack", the honest summary is: Trezor was not hacked; a company that ships Trezor's parcels was, and it leaked customer contact details. The risk that creates is deception, not theft of keys. The rest of this article is about that risk.

What happened, and when

The chain of events, drawn from Trezor's disclosures, Metabase's own security advisory and independent reporting: 2 to 3 August 2026. Attackers exploit a previously unknown flaw in Metabase, a widely used business analytics tool, in a campaign that hits multiple companies. Metabase's post-mortem says a cloud customer reported suspicious activity on 3 August and the flaw was blocked the same day. 6 August. Metabase publishes patched versions and a security advisory for the vulnerability, catalogued as CVE-2026-72898 and rated the maximum severity of 10.0, confirming active exploitation. According to notification emails reviewed by BleepingComputer, Metabase told ShipMonk on the same day that an unauthorised party had accessed data relating to its account and its customers. 8 August. End of the affected order window for the first group of customers. 10 August. ShipMonk informs Trezor of unauthorised access to systems containing Trezor customer data. 13 August. Trezor publishes its disclosure and emails affected customers from help@trezor.io. Trezor describes it as the first incident since 2013 to expose customers' phone numbers and shipping addresses. 14 August. Trezor clarifies that the partial-exposure group of 1,947 customers "does include older orders". 2 September. ShipMonk tells Trezor the breach was larger than stated and included data from 2019 to 2021. 4 September. Trezor publishes the update, emails the newly affected customers, and warns of "fraudulent letters" and "physical security risks" alongside phishing. The actual date attackers entered ShipMonk's systems has not been published by anyone. Reports attributing the wider Metabase campaign to the ShinyHunters extortion group exist, and BleepingComputer reported that ShipMonk received extortion emails, but attribution for the ShipMonk theft specifically remains unconfirmed. As of 7 September, Trezor has said it is not aware of the data being published or offered for sale, and no phishing campaign using this dataset has been documented.

What was exposed, and what was not

The figures from Trezor's own disclosure. In the first group, 11,742 customers had their full name, email address, phone number and shipping address exposed, and a further 1,947 had a partial record exposed showing name, city and email address. In the September group, roughly 67,000 US customers had name, email address, phone number, shipping address and order number exposed. Trezor states that the contents of parcels were not in the data, so the stolen records do not say which device you bought. They do say you bought from Trezor, and nobody needs a packing list to guess what that means. Just as important is what was not there. Trezor states that no Trezor system, product or service was affected and that devices remain secure. ShipMonk's role is delivery, so it never held wallet backups, private keys, PINs or Trezor account passwords, and none of those could have been taken from it. Card payments on Trezor's shop are processed by a separate payment provider, not the fulfilment partner, though Trezor has not made a specific statement about card data in relation to this incident. The recovery phrase you wrote down at setup is the only thing that can spend your coins, and it was never within reach of this breach. Customers who bought through Amazon are not affected, Trezor told CoinDesk, because those orders are fulfilled by a different partner.

Are UK Trezor customers affected?

Yes, for the first group, and explicitly so. Trezor's disclosure names the countries whose customers could be affected by the May to August 2026 exposure: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. If you ordered directly from Trezor's shop and the order was delivered between 10 May and 8 August 2026, work on the assumption that your details leaked. A smaller number of older orders are in the partial-exposure group. For the September group, Trezor's wording is US customers only, for orders between November 2019 and August 2021. Trezor has not said UK customers from that period are affected. If you ordered from the UK in those years and have heard nothing, Trezor's position is that you are not in the exposed data. Trezor's test is simple: "If you did not receive an email from help@trezor.io, then you are not affected." Check the inbox you used for the order, including spam, and check any old address if you have changed email since 2021. Then verify anything you receive by typing trezor.io into your browser rather than clicking a link, because criminals routinely impersonate a company's own breach notification. After Trezor's January 2024 support portal incident, phishing arrived within days from a genuine-looking sender. If you want certainty rather than an absence of email, you have a legal route. Under UK data protection law you can send Trezor a subject access request asking what personal data of yours was involved in the incident and whether it was in either dataset. Trezor is a Czech company but sells to UK customers, so UK GDPR applies. The ICO's guidance for people affected by a breach, updated on 21 August 2026, explains what you can ask for and notes that the organisation has 30 days to acknowledge a complaint.

Why leaking a hardware wallet owner's address is different

A leaked customer list from a clothing retailer tells a criminal that you buy clothes. A leaked customer list from a hardware wallet maker tells them something far more specific: that a named person at a known address has gone to the trouble of buying a device whose only purpose is to hold cryptocurrency. It does not tell them how much. It tells them you are worth a closer look. The first consequence is targeted phishing, which works far more often than the mass version. An email that greets you by name, quotes a real order number and references a purchase you actually made sails past the filter that catches generic spam. Expect fake firmware updates, fake refund offers, fake breach notifications and fake urgent warnings, by email, text, phone and post. The Ledger leak of 2020, in which the names, addresses and phone numbers of about 272,000 customers were dumped publicly, is the case study. Customers received extortion emails, and by mid-2021 criminals were posting tampered fake Ledger devices to leaked home addresses with letters citing the breach. France's data regulator later fined Ledger 750,000 euros over the leak. A separate US lawsuit filed in August 2026 now seeks to trace a later Ledger incident to a $1.95 million theft; our guide to what UK customers can claim after a crypto data breach explains what that case does and does not mean here. Ledger's chief executive was candid that leaked contact data cannot reveal your balance, which is true, and recommended features designed to survive coercion, which tells you how seriously the physical angle was taken. The second consequence is the one Trezor now names directly: physical security. The UK has seen a run of prosecutions for what the police call wrench attacks, where victims are forced to unlock wallets in person. In May 2026, Hertfordshire Constabulary reported five sentences for an attack in which a man was followed home from Shoreditch and forced to unlock crypto and bank accounts. His victim statement described "the horrible feeling of strangers having ongoing access to my personal life, not knowing if the defendants had retrieved information from my phone of where my new residence was". In November 2025 three teenagers were jailed for a Hoxton home invasion in which they posed as delivery drivers and stole about £3 million in ether, most of it later recovered. In August 2026 a London jury convicted five men of imprisoning two French crypto investors for two days in Canning Town. Proportion matters here. In none of those UK cases did the court find the victim was located through a vendor data breach; the evidence pointed to social media, chance encounters and prior acquaintance. Chainalysis documented 46 violent incidents worldwide in the first half of 2026, notes that home invasions were the most common type, and is explicit that such attacks "remain rare events in absolute terms". The point is not that a leaked address makes an attack likely. It is that the exposed dataset is precisely the kind of information such attackers need, which is why UK police advice on wrench attacks now asks holders to "be mindful of the personal information available about you online e.g. home address, workplace or phone number". Publicly discussing what you hold compounds this: the leaked list says you are probably a holder; a social media post saying how much turns a name into a target.

What should Trezor users do now: a UK checklist

First, harden the assumption. Treat every unsolicited crypto-related message from now on as hostile until proven otherwise, whether it arrives by email, text, phone or letter. Your recovery phrase never gets typed into a website, an app or a "validation tool", and it is never read out on a call. Trezor will not ask for it. Nobody honest will. Second, secure the email account tied to the order, because it is the one address criminals now hold. The NCSC's advice since April 2026 is to use a passkey where the provider offers one, and otherwise a strong unique password with two-step verification. If the same password is used anywhere else, change it there too. Consider a fresh email address for anything crypto-related going forward. Third, use the free UK reporting routes, because every report helps take down criminal infrastructure. Forward phishing emails to report@phishing.gov.uk, the NCSC's Suspicious Email Reporting Service, and forward scam texts to 7726. If you have shared information or lost money, contact your bank immediately, then report to Report Fraud, which replaced Action Fraud in December 2025, on 0300 123 2040 (in Scotland, call 101). Be alert to the follow-up scam: "recovery" services that contact victims offering to get their money back, which the FCA warns are usually the same fraudsters. Fourth, use your data rights. Ask Trezor, by subject access request, what data of yours was involved. If you are unhappy with the response, you can complain to the ICO free of charge. The ICO cannot award compensation, but a complaint record matters, and the September retention failure is a legitimate thing to ask about. Fifth, if your home address was in the data, think about the physical layer. Do not confirm to any caller or visitor that you own crypto. Do not keep the hardware wallet, its backup and the packaging in the obvious place. Consider whether anything online, from social media to a public wallet address, connects your name to a balance. If you ever receive a threat, contact the police; the ICO's guidance says the same. Sixth, read the NCSC's guidance on data breaches, reviewed in May 2026, which stresses one point that applies here: phishing "may be sent some time after the breach is made public". The window does not close in a week.

How to recognise a Trezor phishing or recovery scam

Trezor's official scams and phishing page lists the only email domains it uses: @trezor.io, @invity.io, @vexl.it, @tropicsquare.com and @satoshilabs.com. It says that "Trezor will never contact you about your wallet backup or ask you to perform actions with your wallet", and that any message claiming to be from Trezor by text, WhatsApp, Telegram, phone call or postal letter should be treated as phishing. Trezor does not offer phone support at all. Watch for look-alike domains such as trezorr.io. A genuine sender address is not proof of safety. In January 2024 phishing was sent from noreply@trezor.io after a third-party mailing service was compromised. So the rule is not "check the domain" but "never act on the message". If an email tells you to update firmware, verify a wallet, migrate to a secure wallet, claim a refund or confirm your details, ignore the link and go to trezor.io yourself. Firmware updates happen through Trezor Suite, which you should download and verify only from Trezor's own site or GitHub. Current patterns to expect, all of which Trezor has warned about since the update: emails and letters that quote your real name, address and order number to seem authentic; calls from "Trezor support" or "the police" about suspicious activity on your wallet; QR codes on printed letters leading to fake wallet pages; and offers to help you "secure" or "move" funds after the breach. Every one of these ends the same way, with a request for your recovery phrase or a request to sign something. The moment either appears, the conversation is over. Anyone who wants your seed is the attacker. The wider FCA guidance on protecting yourself from scams applies: hang up on anyone pressuring you to act quickly.

Should I move my coins?

Nothing about this incident requires it. The breach exposed shipping records, not keys, and Trezor's guidance focuses on vigilance, not migration. More to the point, panic migration is the attack. The most dangerous message you could receive this month is one that looks like Trezor, tells you your wallet is compromised, and helpfully offers a migration tool or asks for your seed to move you to a "secure wallet". Acting calmly and unprompted is the entire game. If, knowing all that, you would simply sleep better on a fresh seed, that is a reasonable personal choice. Do it on your own initiative, on the device itself, with no website or support agent involved: set up the new wallet, back it up properly, then send funds from the old wallet to the new one and verify the receiving address on the device screen. Our guide to backing up a Trezor covers the process. What you should not do is replace the device because of this incident. The hardware was never the problem. The distinction worth holding onto is between protecting the asset and protecting the person. The asset was protected by cryptography and still is. The person is protected by scepticism, good account hygiene, and not advertising. Those are the controls this breach actually tests.

What the breach means for high value holders

If your holdings are large enough that a determined criminal would consider a visit worthwhile, a leaked name and address changes your threat model more than it changes anyone else's. Three adjustments are proportionate. Reduce what a single coerced act can lose. A passphrase-protected hidden wallet, or a multisignature setup where no single device or person can move funds alone, means that being forced to unlock a device does not hand over everything. Our guide to bitcoin multisig security explains the trade-offs. Academic research on wrench attacks from UCL and Cambridge found that "users with advanced security experience were not immune", which is an argument for designs that assume you might be coerced, not for hoping you will not be. Separate identity from location and from holdings. Have the device, its backup and any documentation stored so that the address in ShipMonk's database is not also the address of the backup. Avoid anything public that links your name to a balance: block explorer bookmarks, screenshots, forum posts, and casual conversation. Assume persuasion, not force, is the likely vector. The realistic attack on a wealthy holder is a patient, well-informed social engineering campaign using exactly the data that leaked. Our adviser playbook on persuasion attacks covers how these unfold and how families can agree in advance that no request for keys will ever be honoured, whoever appears to make it.

The pattern: parcels leak, vaults hold

Zoom out and this is not really a Trezor story. Ledger's e-commerce database leaked in 2020. Trezor's newsletter list leaked through Mailchimp in 2022, and its support portal was breached in January 2024. Ledger customers were exposed again in January 2026 through Global-e, a third-party commerce provider. SafePal disclosed on 16 August 2026 that an order-tracking flaw had exposed around 39,800 customers. Now ShipMonk, twice. In every single case the disclosure carries the same reassurance: devices, keys and funds were not affected. That consistency is the lesson. The cryptography keeps holding. The paperwork around it keeps leaking, because every purchase, delivery, support ticket and newsletter creates a record held by someone whose security you cannot audit. The September update adds a sharper point: even a record you were told had been deleted may still exist. Our piece on who knows you own bitcoin maps the full trail. The practical response is not to stop using hardware wallets, which remain the right tool. It is to treat your identity as part of the attack surface, and to be deliberate about which of your details end up where.

What the Trezor breach teaches about crypto inheritance

There is a longer-term question hiding inside this incident, and it is one most coverage misses. A breach like this is dangerous because it connects a real identity to the likely existence of crypto. Yet a crypto inheritance plan has to do exactly that, on purpose. Your executor or family needs enough information to discover that the assets exist, find where control of them sits, and recover them. Otherwise the coins are lost when you die or lose capacity, which happens far more often than theft. So there is a genuine tension. Too little information and the assets die with you. Too much in one place and you have written the document every attacker in this article would want: a name, an address, a list of holdings, the location of the hardware, and the credentials that control it. A will is the wrong place for any of that, and it becomes a public document after probate in England and Wales, so a seed phrase in a will is a seed phrase published. Our guide on how to leave crypto in a will covers what belongs there instead. The way through is compartmentalisation, and it is the same principle that protects you against a leaked address. Separate three things that are usually conflated. First, that an asset exists, and roughly what it is, which can be documented with no security consequence at all. Second, where control sits, which can be described without disclosing anything that grants control: the kind of device, the fact that a backup exists, and where. Third, the authority to act, which is your executor's appointment and is handled by the will. Only the second needs any care, and it never requires the credentials themselves to be written next to your name. Designing the plan so that no single leak of any single document exposes identity, location and keys together is the whole discipline, and it applies to incapacity as much as death. Our continuity pack checklist for executors sets out what that looks like in practice.

How to store crypto inheritance information safely

Some principles, without operational detail that would help the wrong reader. Keep the map and the keys apart. An inventory that says what exists and who to contact should never be stored with, or contain, the backup that controls it. Someone who finds one should not thereby find the other. Describe the backup's existence and location without reproducing it. "A recovery phrase for the hardware wallet is held at [a specified secure location]" is enough for an executor and useless to a thief. Our guide to seed phrase storage covers the physical side. Use a passphrase or a split backup where the holdings justify it, so that the backup on its own is not the whole key, and record separately who holds the missing piece. Keep the physical location private, including from the shipping address. The lesson of this breach is that the address a company holds for you can leak. The place your backup lives should not be inferable from it. Nominate trusted contacts and tell them the shape of the plan, not its contents. They need to know a plan exists, who the executor is and where instructions will be found, not the instructions themselves. Plan for incapacity, not just death. A lasting power of attorney does not by itself give anyone your recovery phrase, and a hospitalised holder cannot supervise a recovery. Decide in advance who does what. Keep it maintainable. Hardware and software change, addresses change, and a plan that names a device model from 2021 with no update is a plan that fails. Review it when you change wallets, move house, or change the people in it. Our crypto inheritance checklist turns these into a step-by-step list.

After the breach: watching and continuity

Two longer-term actions turn this incident into a prompt for better security rather than a lingering worry. The first is monitoring. A leak like this raises the value of knowing immediately if coins ever move without you. Bitzo's Watchtower is watch-only address monitoring from Bitzo's own bitcoin node: it never holds keys, and the addresses you enrol stay on that node rather than being pasted into a public block explorer. It is included with the Continuity Plus plan for up to 3 addresses and with Private Client for up to 20. The second is continuity. This breach is a reminder that being known to hold crypto has consequences, and one of them arrives on the day you are no longer here to manage it. Bitzo exists to help people plan how digital assets can be securely identified and passed on, through verified contacts and a documented recovery process, without ever handing over the credentials that control them and without Bitzo holding keys. That is the compartmentalised design described above, run as a service, and it is where the security question and the inheritance question turn out to be the same question. The two-minute Bitcoin Inheritance Readiness Scorecard is a good place to see how your current arrangements measure up, and our inheritance planning page explains how the process works.

Frequently Asked Questions

Was Trezor hacked in 2026?

No. Trezor's systems, products and devices were not breached. The intrusion happened at ShipMonk, a third-party fulfilment company that ships Trezor orders, via a vulnerability in Metabase analytics software. What leaked was delivery information: names, email addresses, phone numbers and shipping addresses. No private keys, wallet backups, PINs or passwords were involved.

How many Trezor customers were affected?

Trezor's August disclosure covered 13,689 customers (11,742 with full exposure and 1,947 with partial exposure) from orders between 10 May and 8 August 2026. On 4 September 2026 Trezor said a further approximately 67,000 US customers from orders between November 2019 and August 2021 were also exposed. Trezor has not published a combined total; the figure of roughly 80,700 used in some reports is the two numbers added together.

Are UK Trezor customers affected?

Yes, for the May to August 2026 orders: Trezor explicitly names the UK among the seven affected countries. The September expansion is described by Trezor as US customers only, from 2019 to 2021 orders, and Trezor has not said UK customers from that period are affected. Trezor's test is that if you did not receive an email from help@trezor.io, you are not affected.

Were Trezor seed phrases or private keys leaked?

No. Seed phrases (wallet backups) and private keys are generated and held on the device and in your own physical storage. They never pass through a shipping system, so they could not have been in ShipMonk's data. Nobody can spend your coins using the leaked information.

Is my crypto safe after the Trezor data breach?

Yes, in the sense that matters: keys were never exposed, so the leaked data cannot move your funds. The real risk is deception. Criminals now have enough detail to send convincing personalised phishing by email, phone and post, and Trezor has also warned of physical security risks for people whose home address was exposed. Your defences are scepticism, account security and not advertising what you hold.

Should I move my crypto to a new wallet?

The incident does not require it, because keys were not exposed. Never move funds because an email, call, letter or pop-up told you to; that is the scam. If you independently prefer a fresh seed, create the new wallet on the device itself, back it up properly, and move funds on your own initiative with no website or support agent involved.

What was ShipMonk supposed to have deleted?

Trezor says its contract and data policy required ShipMonk to delete or anonymise order data 90 days after delivery, and that it "repeatedly requested and received written assurance confirming the deletion". The September update revealed ShipMonk still held Trezor order data from November 2019 to August 2021. Trezor has not published the assurances, and ShipMonk has made no public statement.

Can criminals steal my bitcoin with just my name and address?

Not directly. Nothing in a shipping record can sign a transaction. The data is used for targeting: personalised phishing, fake support calls, fraudulent letters and, rarely, physical intimidation. UK police have prosecuted several so-called wrench attacks on crypto holders, though no UK court has linked one to a vendor data breach, and Chainalysis describes such attacks as rare in absolute terms.

How do I report a crypto phishing attempt in the UK?

Forward suspicious emails to report@phishing.gov.uk and scam texts to 7726, both free. If you have lost money, contact your bank first, then report to Report Fraud, which replaced Action Fraud in December 2025, at reportfraud.police.uk or on 0300 123 2040. In Scotland, call Police Scotland on 101.

Can I claim compensation for a data breach in the UK?

You have rights under UK data protection law: you can ask Trezor what data of yours was involved, and you can complain to the ICO free of charge if you are unhappy with the response. The organisation has 30 days to acknowledge a complaint. The ICO itself cannot award compensation; that would require a civil claim, for which you should take legal advice.

What happens to a Trezor wallet when the owner dies?

Nothing automatic. The device and its recovery phrase are the only route to the coins, and if nobody knows they exist, where the backup is, or how to use it, the assets are lost. The safe approach is to document that the assets exist and where control sits, without writing the recovery phrase in a will (which becomes public after probate) or in the same document as your identity and address.

Sources

Ready to plan your crypto inheritance?

Speak to our UK-based team about your situation. No obligation, no pressure.

Speak to us