Trezor Breach Exposes Thousands to Physical Attack Risk
A recent breach of Trezor's shipping partner ShipMonk has exposed thousands of users to physical attack risk, adding bearish pressure on Bitcoin's near-term price.
The incident, which occurred via a Metabase SQL injection zero-day, leaked names, emails, phone numbers, and addresses for 11,742 customers in full and 1,947 more partially. The breach affects buyers from various countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor warns that exposed users face targeted phishing and social-engineering attacks, as attackers can use the leaked data to impersonate banks, exchanges, or Trezor itself to extract wallet recovery seeds. This is not the first breach of this kind for Trezor, as a January 2024 breach of its support portal exposed 66,000 users and led to direct phishing attacks.
The second supply-chain incident within eight months deepens reputational risk for hardware wallet adoption, a sentiment headwind for Bitcoin's self-custody narrative. Physical crypto theft exceeded $30M in H1 2026, with home address leaks as a key enabler.