The forty-third field guide in our Reading Room series takes a document type that most Bitcoin holders will receive at least once and few will read past the first paragraph: a data-breach notice from a company that sold them a hardware wallet. Trezor published one on 13 August 2026 and updated it on 4 September to add approximately 67,000 US customers from a 2019–2021 shipping contract to the 13,689 disclosed in August; today’s lead has the news. Ledger’s 2020 e-commerce breach, which exposed roughly 270,000 customers’ addresses and was followed by years of phishing letters and at least one wave of fake replacement devices sent by post, is the case every reader of this guide should hold in mind, because it is the template for what happens in the months after a notice, not the days. The guide has six questions, two risks, five actions and one marker. It is scored on Trezor’s notice as read at 06:10 UTC on Sunday 6 September, and quotations are verbatim from that text.
Question 1: Who held the data, and why did they have it?
The first thing a notice should tell you is whose systems were entered, and the answer is very often not the company whose name is on the box. Physical products need to be stored, packed and delivered, and a company shipping worldwide does that through fulfilment contractors which, to do its job, needs your name, address, phone number (carriers require one) and email. Trezor’s notice answers this directly: ShipMonk “is the logistics partner that stores our products and ships orders to customers in the US, UK and several other countries,” and holds that data because “that is the only reason they hold any of your data.” The test to apply is whether the notice says so plainly or hides the contractor behind “a third-party vendor.” Trezor names ShipMonk in the first line. Score: the reader can identify the entity that lost the data and the reason it existed there. That matters for the next question, because the type of holder determines the type of data.
Question 2: Which fields, exactly — and which fields are structurally impossible?
A notice should list the fields, and a reader should compare the list against what the holder could possibly have had. A shipping contractor can have name, address, phone, email, order number and, sometimes, what was in the parcel. It cannot have a private key, a recovery phrase, a PIN or a device serial tied to a wallet, because none of those exist at the time of shipping — the device generates its keys when the owner first sets it up, and the backup is written on paper by the owner. Trezor’s notice lists the fields for both tranches (name, email, phone number, shipping address, order number for full exposure; name, city, email for the 1,947 partial-exposure records) and states the exclusions: “our systems were not compromised, and your Trezor device is secure,” “No Trezor system, product, or service was affected,” and “The contents of the parcel were not exposed in this breach.” The exclusion that a careful reader will notice is missing is the payment card, which a fulfilment house would not usually see but a payment processor would; the notice does not mention cards, and the reader should take that as “not in this dataset” rather than “safe,” and check the card statement anyway. If you want the underlying reason a leaked address cannot reach your coins, our guide to where a seed’s security actually comes from covers it.
Question 3: What time window, and does the window match the retention policy?
Here is where Trezor’s notice is the most instructive document of its kind we have read, because it shows the test being applied and failing. The August notice bounded the exposure by policy: Trezor requires partners to delete or anonymise order data 90 days after delivery, so “only orders received within 90 days before August 8th, 2026, were affected, as older data had already been deleted.” That is a claim about the contractor’s behaviour, not a fact about the dataset, and the 4 September update records what happened when the dataset was examined: it “also contained order data from our prior cooperation between November 2019 and August 2021.” Trezor adds that it “repeatedly requested and received written assurance confirming the deletion of the data.” The rule for the reader is simple. When a notice says older records were not affected because of a retention policy, the window is a policy window, not an observed one, and the only observed window is the one the attacker’s dataset defines. A well-written notice will say which of the two it is giving you. Trezor’s August notice did not make that distinction; its September update does, at the cost of about 67,000 people. Score: the reader now has the observed window for the full-exposure records (May–August 2026 for seven countries; November 2019–August 2021 for the US) — the 1,947 partial records’ timeframe is still, in Trezor’s words, being verified — and a worked example of why the policy window was not enough.
Question 4: How did the holder get in, and does the notice say?
The attack vector tells you whether the leak is likely to be one dataset or many. Trezor’s notice says only that ShipMonk reported “unauthorized access to their systems containing customer data,” that the investigation is ongoing and that ShipMonk “has secured the affected systems.” Cyber Security News reports that ShipMonk told its own customers the entry was through a vulnerability in Metabase, an analytics platform, and that Metabase notified ShipMonk on 6 August. A flaw in an analytics tool that sits on top of a warehouse’s whole database is consistent with a broad extraction rather than a targeted one, which is why the reader should expect other ShipMonk merchants’ customers to be in the same dump and should not assume the Trezor data was singled out. The notice does not give the vector; the reader has to go to the trade press for it. Score: partial.
Question 5: Phishing risk versus physical risk — rank them, do not merge them
A notice that lists “phishing and physical security” in one breath is doing the reader a disservice, because the two risks differ by orders of magnitude in likelihood and require different responses. Phishing is near-certain. The Ledger precedent produced, within weeks, emails and SMS messages purporting to be from the company, and within months physical letters on convincing letterhead asking customers to “update” their device by entering their recovery words into a website, plus a smaller number of counterfeit devices mailed to victims with a pre-printed recovery card. Every one of those attacks succeeds only if the victim types or reveals the backup. Trezor’s notice puts the defence in bold: “Never enter your wallet backup on a website or share it with anyone.” That sentence, obeyed, defeats the whole phishing category. Physical risk — the so-called wrench attack — is real, rare, and the one the shipping address enables; it is also the one that a leaked six-year-old address is least useful for, because people move, and the one for which the countermeasure is not a setting on the device but a decision about how much is held on a wallet that ships to a home. Trezor’s update names both risks in that order, phishing first. Score: the notice ranks them correctly; the reader should keep the ranking.
Question 6: What is the company changing, and has it put a date on it?
The last thing to read for is the fix, and whether it has a date. Trezor’s notice describes four things a customer can do today — an email address not linked to their identity, payment in crypto or by disposable card, a P.O. box, with the honest caveat that the postal service will still hold an ID — and one it has not yet shipped: “Anonymous Delivery (coming soon) lets you receive your hardware wallet more privately by using a dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery.” The date is in the next sentence: “We aim to make this shipping option available in the EU by September 2026 and in the US by the end of 2026.” A promise with a month attached is a promise that can be graded, and we grade it below. Score: the notice gives a fix and a date, which is more than most.
Five things to do this weekend, in order of usefulness
First, decide now, while nothing is happening, that you will never type your recovery words into anything with a screen, and tell the people you live with the same. That one decision removes the phishing risk entirely and costs nothing. Second, if you received Trezor’s email, or bought any hardware wallet from any manufacturer by mail since 2019, treat every unsolicited message or letter about your wallet as hostile by default and verify only through the manufacturer’s site typed by hand, never through a link. Third, if the amount held on a device that was shipped to your home is large relative to what you would be prepared to lose in a confrontation, read our guide to multisignature and split custody: a setup in which no single location holds enough keys to move the coins is the only real answer to the physical risk, and it is a weekend’s work. Fourth, if the leaked address is your current one and you are uneasy about it, the cheapest fix is to make sure the wallet’s passphrase feature is in use with a decoy wallet on the base seed, so that a device surrendered under duress surrenders a small balance. Fifth, next time you order, use the private-ordering steps the notice lists, or wait for the anonymous option and buy through it. Our hardware-wallet comparison covers the main manufacturers; ask each one, before ordering, what it does with your address after delivery.
The marker
As standing practice we mark one falsifiable claim on the subject of this guide. S1: on or before Wednesday 30 September 2026, Trezor’s Anonymous Delivery option is available to customers ordering from at least one EU country, as evidenced by the option appearing on trezor.io’s checkout or by a dated Trezor announcement that it is live. The reasoning is that the company put “by September 2026” in writing on 13 August, twenty-four days ago, and has repeated it in the trade press since; the counter-argument is that a new fulfilment channel with lockers and identifier deletion is a logistics project, not a software toggle, and that companies miss self-imposed dates on those routinely. If it grades as a fail, the desk will have taken a stated aim as a commitment. We will grade it against the Trezor site and blog, not against reports. The Reading Room’s hub indexes all forty-three guides, including #42 on Treasury yield headlines, published yesterday.
Disclaimer: This article is for informational purposes only and does not constitute investment advice. Cryptocurrencies are volatile and you can lose money. Nothing here is a recommendation to buy or sell any security, digital asset or exchange-traded fund, including MSTR. Do your own research and consult a licensed financial advisor before making investment decisions.