In short
- The leak came from an outside fulfilment provider, not from Trezor's own systems Trezor states its core systems and its devices are unaffected.
- 13,689 customers are affected 11,742 had the full record exposed; a further 1,947 lost only name, city and email.
- What is out: names, shipping addresses, emails and phone numbers Recovery phrases and private keys were not in this data, and are never sent to a shipping provider in the first place.
- Thailand is not among the affected countries The seven are the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
- The real risk is fraud and physical safety This is a list that identifies who owns a hardware wallet, and where they live.
- Customers who bought from SIAMBC are not affected by this incident Orders placed through a distributor in Thailand were not shipped by the provider that was breached.
On 13 August 2026 Trezor disclosed that data on 13,689 customers had leaked. The source was not the company's own systems but an outside fulfilment and warehousing provider that Trezor uses.
Some outlets name that provider as ShipMonk, while others describe it only as a shipping provider. The company name should therefore be treated as reported rather than confirmed across sources.
What happened
A fulfilment provider is the company that packs and ships orders on the maker's behalf, which means it necessarily holds the recipient details. When that provider's systems were breached, those recipient details went with them.
The breach window is reported as 10 May to 8 August 2026, though that timeframe appears in some reports only and is not stated consistently everywhere.
Trezor states that its own core systems remain secure, and that devices and wallet backups are unaffected.
What was exposed
11,742 customers had a complete record exposed: name, shipping address, email and phone number. A further 1,947 lost only name, city and email. 13,689 in total.
| Data | Status | Note |
|---|---|---|
| Full name | Leaked | Part of the delivery record |
| Shipping address | Leaked | The most dangerous item in this set |
| Leaked | Used for scam mail aimed at a named person | |
| Phone number | Leaked | Used for calls and messages posing as support |
| 12 or 24-word recovery phrase | Not leaked | Generated on the owner's device, never sent to the maker or the shipper |
| Private keys | Not leaked | Never leave the device to begin with |
| PIN | Not leaked | Set and held on the device only |
| Balances and transaction history | Not leaked | The maker does not hold this |
What was not exposed is the recovery phrase, the private keys and the PIN. The reason is simple: none of those ever leaves the owner's device. The maker does not hold them, and a shipping provider is even further from them.
Why this is worse than it looks
Reading that the keys are safe, many people conclude there is nothing to worry about. That is wrong. What leaked is a list of people confirmed to have bought a hardware wallet, together with their home address and phone number.
The first risk is fraud. Anyone holding this list can email or call knowing the real name, knowing which model was bought, and knowing the address, which makes an invented story far more convincing than an untargeted one. The destination is always the same: getting the victim to type a recovery phrase somewhere.
The second risk is physical safety. A list showing who probably holds crypto and where they live is valuable to anyone planning something at the address. Trezor itself warned customers to watch for both scams and intrusion.
Three shapes to watch for
1. Email phishing. Mail claiming to come from Trezor, saying the account has a problem, that identity must be confirmed, that firmware needs an urgent update, or that because of the leak the wallet must be recovered. These carry a link to a page that looks genuine and has a field for the recovery phrase. The test that always holds: there is no situation in which a recovery phrase belongs in a web page, however convincing that page looks.
2. Fraudulent mail through the post. This is the most dangerous shape here, because home addresses are out. Criminals have previously sent envelopes made to look like they came from the maker, carrying instructions to scan a QR code, or sent a free replacement device that had already been tampered with, claiming the original was compromised by the leak.
The safest rule is never use a device you did not order yourself. Makers do not send unrequested replacements, and they do not post paperwork asking for a recovery phrase. Anything arriving that way should be treated as fake until proven otherwise.
3. Fake customer support. Calls, messages or accounts posing as the team, reaching out already knowing the real name, the model bought and the address, which makes them read as legitimate. Some work by getting the victim to call back a prepared number, or by opening a conversation on Telegram, X or a group chat.
The simplest test is that a real support team never makes first contact to ask about a wallet, and never asks anyone to reveal a recovery phrase, by phone, by chat or over a shared screen. To reach support, go to the maker's or the shop's official channel directly rather than following a link that arrived.
Are customers in Thailand affected
Seven countries are affected: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Thailand is not on that list.
Customers who bought their Trezor from SIAMBC are not affected by this incident, because an order placed through a distributor in Thailand was not shipped by the provider that was breached, which is the provider Trezor uses abroad. Those customers were never in the leaked set to begin with.
In any case SIAMBC has never asked for and never keeps a customer's recovery phrase or private keys, because those are created on the customer's own device after the box is opened. They never pass through a shop.
Anyone who ordered directly from Trezor's website to an address abroad should check their email for a notification.
That said, leaked lists are commonly resold and reused far beyond the original set, so treating unexpected mail with suspicion is worth doing wherever you live.
What Trezor owners should do
Do not move your coins, and do not change your recovery phrase. Nothing in this data puts anyone's keys at risk, and generating a new phrase in a hurry introduces more opportunity for error than it removes.
Assume every email claiming to be from Trezor is fake. Especially any that asks you to confirm your identity, update firmware through a link, or reports a problem with an account. To update firmware, always open the maker's own app rather than following a link in a message.
Never type a recovery phrase into any website or app. There is no situation that calls for it, and no maker or shop will ever ask to see one.
Anyone whose address is out should be wary of parcels they did not order, and of people making contact on the pretext of a delivery, which is a way of establishing whether somebody is home.
The lesson that applies to every brand
This is not a flaw in hardware wallets, and it is not confined to Trezor. Every maker that ships to a customer's door has that address sitting in somebody's system, and the delivery chain is the part a maker controls least.
What the incident confirms once more is that a design that keeps no keys at the maker actually works. An entire customer list was exposed and not one coin moved, because the keys were never in the system that was breached.
Trezor says it will offer anonymous delivery to parcel lockers, starting in Europe within September and in the United States by the end of the year.
Common questions
Are my coins safe? Yes. The leaked data contains no recovery phrase, no private keys and no PIN, and none of those has ever existed outside the owner's device.
Should I generate a new recovery phrase? No. Changing the phrase means moving every coin, which carries risk of its own and does nothing about the risk this incident actually created.
Buying in Thailand
SIAMBC has been an authorized Trezor distributor in Thailand since 2016. Everything is new and factory sealed, delivery is free nationwide, and there is a shop in Bangkok for anyone who would rather collect in person than give a delivery address at all.





Share:
What is a hardware wallet, how it works, and who needs one