August 19, 2026 - Staff
Milan, 19 August 2026 - In recent days Trezor disclosed that ShipMonk, the supplier that stores and ships its hardware wallets, suffered a data breach: the name, shipping address, phone number, email and order number of nearly 14,000 customers were exposed. No private key was touched, and no crypto-asset was moved. But that is precisely the point worth examining: when the keys stay safe yet a person’s identity and home address get out anyway, the risk doesn’t vanish - it transforms. And it’s a risk that concerns anyone who self-custodies crypto-assets, not just Trezor customers.
ShipMonk notified Trezor of the unauthorised access on 10 August; the public disclosure came on 13 August. The exposure affects 11,742 customers with complete data (name, email, phone, address) and 1,947 with partial data, covering orders delivered between 10 May and 8 August 2026 across seven countries, Italy included. Damage was limited by a data-retention policy that requires the deletion of orders older than ninety days. Trezor has already announced an anonymous delivery option arriving by the end of 2026.
An email on its own is of little value to a scammer. A name, home address and phone number together, however, identify a specific person - one who in recent weeks purchased a device whose sole purpose is to safeguard private keys. The most immediate risk is targeted phishing: messages that are fake but credible because they’re built on real data. The less immediate but more serious risk is physical. Physical coercion of crypto-asset holders - so-called wrench attacks - is growing structurally: the public database maintained by Bitcoin security expert Jameson Lopp records over 260 known cases since 2014, while blockchain security firm CertiK counted 52 incidents in the first half of 2026, against 39 in the same period of 2025. Europe’s share rose from 22% to over 40% of the global total, with France in the lead. In 2026 Lopp flagged several cases of mistaken identity or outdated information: once these lists are out, they don’t update and they don’t expire.
The pattern recurs with regularity. In 2020 Ledger suffered an exposure of customer data through an ecommerce partner; in January 2026 Ledger data was exposed at Global-e. Now ShipMonk for Trezor. In none of these three cases was the manufacturer itself breached, and in none of the three did that protect customers: selling a physical device requires a chain of suppliers, each with attack surfaces independent of the manufacturer.
Anyone who received Trezor’s notification should not move their funds: the keys are not compromised, unlike in July’s Coldcard incident. The right steps are different:
”‘Not your keys, not your coins’ describes a real risk - that of relying on an untrustworthy custodian - but it conceals another: if your keys are at home, the point of attack becomes you,” says Ferdinando Ametrano, CEO of CheckSig. ”Self-custody carries not only a technical risk but a personal one, which no firmware update can fix. It must always remain possible, but it should be chosen with a clear understanding of what it entails: the people caught up in this breach made no mistake - they simply bought a device and provided their address to receive it.”
The role of professional custody
In CheckSig’s professional custody, the geography of risk is different for two structural reasons. The first is the separation between identity and physical infrastructure: anyone who entrusts custody to a regulated intermediary doesn’t receive a device at home, and no courier handles the link between a name, an address and a custody device. The customer’s identity is of course still known to the intermediary, but it is subject to a minimisation and retention regime compliant with GDPR, MiCAR and DORA, with an obligation to report incidents to the supervisory authorities.
The second reason is more relevant in light of this specific case: even knowing a customer’s address, an attacker can obtain nothing if that customer is not in a position to move the funds alone, under duress, on the spot. It is the architecture that renders physical coercion ineffective, not the confidentiality of the address. CheckSig applies this principle in its custody protocol: three authorisation stages with multi-signature across a total of eleven keys, distributed among different parties and locations, with time locks that prevent immediate transfer. The verifiability of the model is what makes it a genuine safeguard: hence the public Proof-of-Reserves, the independent SOC attestations and the insurance coverage.