Trezor account hacked? Here’s what to do
Move fast and in the right order: reclaim the account through Trezor’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.
Trezor buyers lost their delivery addresses, not their coins
Trezor said on 13 August 2026 that ShipMonk, one of the partners that packs and posts its wallets, had told it three days earlier that an outsider reached systems holding order data. By Trezor's count, 11,742 customers had a name, email address, phone number and shipping address exposed, and another 1,947 had a name, city and email. Trezor's own systems, your device, your private keys and your wallet backup are not part of this, so there is no password here for anyone to reset. What did get out is a list of people known to keep crypto at a specific street address, which is why the company is warning about far better-aimed phishing rather than about your seed.
Trezor, "Recent customer data exposed in shipping provider incident", 13 August 2026. Reported by CoinDesk, BleepingComputer, SecurityWeek, Bitcoin Magazine and Protos, 13-14 August 2026.
If your Trezor account was hacked: start recovery at the official page (trezor.io/learn/security-privacy/personal-security-standards/scams-and-phishing), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.
Recover your Trezor account, step by step
These steps follow Trezor’s official process — expect it to take nothing to reset on the device; pulling the address back off the public web takes weeks. Official links only: account recovery · password reset.
Start by doing nothing with your wallet backup. No genuine Trezor process needs those words: not support, not a firmware update, not a breach notice. This incident did not touch them, and the phishing that follows it exists to make you type them somewhere.
Work out whether you are on the list. The exposure covers orders received between 10 May and 8 August 2026 shipped to the US, UK, Sweden, Colombia, Brazil, Italy or Portugal, and Trezor emailed the customers it identified. To check the claim, type trezor.io into the address bar yourself instead of following the link in the message.
Change your default on inbound contact for the next few months. A call, letter or email that knows your address and your Trezor purchase proves nothing now. Hang up and dial the number from the company site, and never install or update anything on someone else prompting you to.
If you have already entered your backup somewhere since the news broke, treat that wallet as spent: create a new wallet with a fresh backup on the device and move the funds across before you do anything else. Crypto transactions do not get reversed, so being first is the only defence that works.
Then take the address itself out of circulation. It is also sold, legally, by people-search sites that had it long before this breach, and the phone number with it. Check whether the email you used at checkout turns up in known breach data too, since that is what phishing lists get built from.
What trips people up with Trezor
- The exposed set is unusual, and that is the whole problem. A password breach costs you a password; this one pairs your full name with the address a hardware wallet was delivered to, plus the phone number you left at checkout. Trezor's notice tells affected customers to expect more convincing phishing and names the shapes it takes: fake emails, phone calls, letters through the post, people posing as your bank or your exchange. The address is what makes all of that credible, and there is no reset button for an address.
- There is nothing to change on the device, and that gap is what the scam fills. Trezor states that its systems, hardware wallets, private keys and wallet backups were not affected, so any message telling you to verify or re-enter your wallet backup because of the breach is itself the attack. Nobody at Trezor asks for those words, on any channel, at any time. Typing them into a page that looks right is how the coins leave.
- The exposure has edges. Trezor says it covers orders received between 10 May and 8 August 2026 in seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. It credits its own 90-day retention rule at fulfilment partners for keeping the set that small. If you bought earlier than that window, this particular list is not yours, though your address is probably still sitting on people-search sites, which is the slower and far more public version of the same problem.
- The break-in was not at Trezor. ShipMonk's notification, quoted by BleepingComputer, says an unauthorized party exploited a vulnerability in the Metabase analytics platform; SecurityWeek ties that to the SQL-injection flaw Metabase patched days earlier, notes that the extortion crew known as ShinyHunters claimed the campaign, and reports that ShipMonk had not acknowledged the incident publicly as of 14 August. ShipMonk ships for a lot of brands, so a similar letter from another shop you bought hardware from is plausible rather than fake.
- Expect a second wave with a lawyer's letterhead. Coverage of any breach involving home addresses is followed within weeks by class-action solicitations, some real and some not, and by recovery-service pitches aimed at people already nervous about their crypto. Nobody can reverse a Bitcoin transaction, so anyone promising to claw funds back is selling you the second loss.
Was Trezor hacked, and is my crypto at risk?
No, and the distinction is the useful part. The break-in happened at ShipMonk, a fulfilment company that stores and ships orders for online brands, Trezor among them. ShipMonk told Trezor on 10 August 2026 that an unauthorized party had reached systems containing customer data, and Trezor published its own account on 13 August. That statement is explicit that Trezor systems were not compromised and that hardware wallets, private keys and wallet backups were not affected. Nothing about your device changed that week, and nothing about it needs changing now.
What did leave was order data. By Trezor's count, 11,742 customers had a name, email address, phone number and shipping address exposed, and 1,947 more had a name, city and email address, which is 13,689 people in total. They came from orders received between 10 May and 8 August 2026 in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor says the ceiling exists because it holds order data with fulfilment partners for no more than 90 days, and it warned the people on that list to expect sharper phishing: emails, calls, letters through the post, and impersonation of banks and exchanges.
Two things were still open in mid-August. The cause sits with a third party: ShipMonk's notice, quoted by BleepingComputer, blames a vulnerability in the Metabase analytics platform, and SecurityWeek connects it to a flaw Metabase had just patched and to the extortion group that claimed that campaign, while noting ShipMonk had said nothing publicly. And ShipMonk ships for many brands, so the same intrusion may be the reason a different shop writes to you this month. A genuine notice names what was exposed, comes from the company's own domain or arrives in the post, and never asks you to confirm a wallet backup.
Still logged in? Lock the account down now
If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in Trezor's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.
Got a "new login" alert from Trezor?
Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for Trezor). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.
The attacker spent, moved or stole money
Report the unauthorized transactions to Trezor through the official flow the moment you're back in (or even before — fraud reports don't require account access). U.S. consumer protections for electronic transfers generally limit your liability the faster you report, so speed matters more than completeness. Also call the bank or card issuer behind the funding source — they can dispute, reverse or block further charges — and file at reportfraud.ftc.gov so the pattern is on record.
Why this happened — and how to make sure it can’t again
About a third of account takeovers are credential stuffing: a password you used on Trezor (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when Trezor itself was never breached, your reused password from another site opens it.
So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.
Check my exposure — free →After you recover: three doors to close
- Unique password + 2FA. A password manager plus app-based two-factor stops both stuffing and phishing replays.
- Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
- Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Hacked Trezor account, answered
How did my Trezor account get hacked?
The most common cause isn't a hack of Trezor itself — it's credential stuffing: a password you used on Trezor leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake Trezor login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.
Can I get my Trezor account back?
Usually yes. Use the official recovery flow (https://trezor.io/learn/security-privacy/personal-security-standards/scams-and-phishing) — it can verify you even when the attacker changed the email and password. Expect it to take nothing to reset on the device; pulling the address back off the public web takes weeks; respond quickly to follow-ups so the case stays open.
Should I just make a new Trezor account instead?
Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so Trezor can lock it, before you start over.
Will I get money back that was stolen through my Trezor account?
Often, if you move fast. Report the unauthorized activity to Trezor and to the bank or card behind it — U.S. protections for unauthorized electronic transfers generally limit your losses the sooner you report. Peer-to-peer payments you were tricked into sending yourself are much harder to recover than transactions the attacker made — another reason to report the takeover itself, with evidence.
Was my Trezor wallet or seed phrase exposed in the breach?
No. Trezor says its systems, hardware wallets, private keys and wallet backups were not affected, because the intrusion was at a shipping partner that held order details and nothing else. The exposed fields were names, email addresses, phone numbers and shipping addresses. Your coins are where you left them and there is nothing on the device to reset.
Do I need to move my crypto after the Trezor data breach?
Not because of the breach itself, since your recovery words were never in the leaked data. Move the funds to a new wallet only if you have since typed those words into a website, a chat or an app that asked for them, because producing exactly that mistake is what the phishing wave is for.
Which Trezor customers were affected by the ShipMonk breach?
People whose orders were received between 10 May and 8 August 2026 in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal. Trezor counted 11,742 with a name, email, phone number and shipping address exposed, and 1,947 with a name, city and email. Affected customers were contacted by email.
How did the Trezor data breach happen?
At a supplier rather than at Trezor. ShipMonk, which fulfils some Trezor orders, said an unauthorized party exploited a vulnerability in the Metabase analytics software to reach data, according to notifications quoted by BleepingComputer, and SecurityWeek links the attack to a Metabase flaw patched in early August 2026. Trezor was told on 10 August and disclosed on 13 August.
My home address was leaked, so what can I actually do about it?
You cannot recall it, so the useful move is to shrink what sits next to it. Take your address and phone number off the people-search sites that publish them, put a passcode on your mobile account so the number cannot be ported away, and treat unsolicited calls, letters and emails about your wallet as hostile for a few months.
How do I stop my Trezor account being hacked again?
Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication, and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.