Buy now

If you ordered a Trezor between May and August 2026, there's a chance your name, your home address, and your phone number are sitting in a file that someone else now owns. The Trezor data breach disclosed on 13 August 2026 didn't touch a wallet, a seed phrase, or a coin. It leaked the paperwork around them, and that paperwork turns out to be worth a great deal to the people who make a living calling crypto owners on the phone.

What the Trezor data breach exposed

The incident happened at ShipMonk, the fulfilment provider that packs and ships Trezor orders, rather than inside Trezor's own infrastructure. Per the company's disclosure, reported by crypto.news, 13,689 customers were affected: 11,742 had full records exposed, covering names, email addresses, phone numbers, shipping addresses, and order numbers, while 1,947 had partial records limited to names, cities, and email addresses.

The exposure window ran from 10 May to 8 August 2026, and it covered orders delivered in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor apologised to the people affected and said that its own systems and its hardware wallets were unaffected.

Your device and your coins were untouched

That last point deserves stating plainly, because the word "breach" invites a much worse reading than the facts support. Nothing in this leak gives anyone the ability to move funds. A hardware wallet keeps its security in a private key generated inside a chip, and a shipping database has no relationship to that key whatsoever. No seed phrases were exposed, no firmware was altered, and no device was tampered with in transit as part of this incident.

What changed is softer and much harder to patch. A list now exists that names people who own a hardware wallet, and it pairs each name with a home address and a working phone number.

Why a shipping list is worth stealing

Consider what a scammer normally has to guess at. They need to find someone who holds crypto, work out which brand of wallet that person uses, and then invent a reason for the call that sounds plausible enough to keep them on the line. A fulfilment database answers all three questions at once, with a delivery date attached so the caller can reference the order out loud.

This is why leaks like this one produce phishing waves rather than direct theft. Trezor has been through the pattern before: a compromised third-party support portal in January 2024 exposed contact details for up to 66,000 customers, and BleepingComputer reported that attackers turned around and used those details to approach users and ask them for their 24-word recovery seeds. The 2026 leak is the first in the company's history to include phone numbers and shipping addresses, which raises the quality of the pitch considerably.

The phone calls that followed

Four days after Trezor's disclosure, Rapid7 Labs published research on a fraud pipeline it named Operation ASTERIX, uncovered through a misconfigured directory on the operators' own servers. Researchers Anna Širokova and Jan Recinsky found roughly 885,000 phone numbers staged for calling, alongside tooling that checked each number against crypto exchange accounts before anyone picked up the handset.

The call is the setup. A phishing email opens a fake support case complete with a verification code, and then a caller quotes that code back to you along with your name and your location, which makes the conversation feel like a callback you were expecting rather than a cold approach from a stranger. From there, the victim gets steered toward downloading what appears to be their own wallet software.

The counterfeit Trezor Suite build was the most developed of the three applications the researchers recovered, sitting alongside fake Ledger Live and Exodus builds. It ran as a hidden window, scanned the process list every five seconds for the legitimate application, terminated it, and pushed its own interface to the front, where it asked for the recovery phrase and passphrase and forwarded every word typed into it to a Telegram bot.

Read that sequence again and notice where it succeeds. Every technical control on the hardware wallet held: the secure element kept the key, the firmware did its job, and the device itself was never touched by the attacker. What failed was a person typing twelve or twenty-four words into a window that looked exactly the way it was supposed to look.

What to do if your details were in the file

Trezor is contacting affected customers directly, so treat any approach that arrives through another channel as hostile until you've proven otherwise. If someone calls about your order, hang up and reach the company yourself through the address on its website; a caller who knows your order number has told you nothing except that they read the same leaked file everyone else did.

Type wallet software URLs by hand rather than following a link or a search result, since a phishing site impersonating Trezor has previously reached the top of Google results through paid placement. Watch your email for password reset attempts on exchange accounts tied to the same address. Because home addresses leaked here too, it's worth being alert to physical mail that references your order, and to any unexpected package containing a "replacement" device.

The rule underneath all of this is short enough to memorise. No wallet company, Ryder included, will ever ask you for your recovery phrase, and any screen or voice that does is an attack in progress.

Where your backup lives changes what a phone call can do

Every one of these attacks converges on the same target. The recovery words are the wallet, so a well-built social engineering pipeline doesn't need to defeat a secure element when it can talk a tired person into reading twelve words aloud on a Tuesday evening.

That's the assumption we set out to break when we built TapSafe Recovery. Instead of concentrating your access into one string of words that must stay secret forever and can be surrendered in a single conversation, TapSafe splits it: your Recovery Tag holds 50%, your paired phone holds 50% encrypted into your own iCloud or Google Drive rather than on the handset itself, and optional Recovery Contacts hold 25% each while learning nothing about your wallet. No single piece recovers anything on its own, and none of it is a phrase you can be persuaded to type into a window.

The seed phrase stays available on the device as a last resort, and it follows the BIP-39 standard, so you're never locked to our hardware. On the Ryder One, keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, the firmware was independently audited by Halborn with the full report public, and every transaction renders in readable detail on the 1.6-inch screen before you approve it. Communication runs over NFC and nothing else.

We ship boxes too, and any company that ships boxes keeps a list of where it sent them. What a company can control is how much damage that list enables when it escapes, and an attacker holding your address and your phone number still needs you to hand over something you can recite.

Hold your keys in a way that survives a convincing phone call. Get your Ryder One.


Meta description: The Trezor data breach exposed 13,689 customers' names, addresses and phone numbers via shipper ShipMonk. What leaked, what didn't, and what to do next.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More