Crypto
2026-08-15
People buy hardware wallets like Trezor's specifically to keep their crypto holdings private. The device itself never touches the internet, which is the whole appeal. But Trezor still has to ship that device to your house. This week, the company disclosed that whoever handles its shipping got hacked instead.
The breach didn't touch Trezor's own systems or software. It hit ShipMonk, the outside company that packs and mails Trezor orders. Trezor says the wallets themselves, and any crypto stored on them, were never exposed. That distinction matters, but it doesn't erase the risk. Owning a hardware wallet is a strong signal that someone holds real crypto. Combine that signal with a real name and home address, and scammers have what they need for targeted phishing. In rarer cases, that same information has been used to target crypto holders in person. This breach is separate from a different, larger story about French tax data fueling crypto robberies. The two get confused online, but they're not the same incident.
Will Trezor's customers actually get targeted, or does this stay a phishing-email nuisance? Trezor is telling affected buyers to watch for scam emails and texts pretending to be the company. The bigger question is about the industry, not just Trezor. Crypto hardware makers all rely on outside shippers, warehouses, and customer-service tools they don't fully control. Watch whether other wallet makers disclose similar breaches at their own vendors in the coming weeks.
This story is written by AI from the sources above, checked against them before publishing. If something here still reads wrong, tell us and we'll correct it.