Newly disclosed US customers
~67,000
Trezor blog update, Sep 4, 2026
Total customers now exposed
~80,689
Sum of Aug 13 disclosure (~13,689) and Sep 4 update (~67,000)
Data fields in scope
5
Name, email, phone, shipping address, order number — no private keys or device compromise
Order window covered
Nov 2019 – Aug 2021
Trezor blog, Sep 4, 2026
Global hardware-wallet market, 2026
$0.72B
Mordor Intelligence forecast, Jul 29, 2026
Violent crypto theft stolen value, 2025
$58M
Chainalysis report on wrench attacks, Aug 6, 2026 (annual record)
The disclosure
Trezor's US exposure just jumped five-fold — and the breach was at a vendor, not at the wallet
Trezor's first disclosure on Aug 13, 2026 covered roughly 13,689 customers whose names, emails, phone numbers, and shipping addresses leaked from ShipMonk, a third-party fulfillment provider the wallet vendor had retained for US order handling. Three weeks later, on Sep 4, Trezor's blog confirmed that ShipMonk had informed the company on Sep 2 that the breach was materially larger than initially stated, adding another ~67,000 US customers whose full details (name, email, phone, shipping address, order number) had sat in the fulfillment vendor's systems from orders placed between November 2019 and August 2021. The cumulative tally now stands at ~80,689 affected US customers — and crucially, the wallet devices, recovery seeds, and on-chain funds of those users were never touched.
| Disclosure | Date | Customers added | Data fields exposed | Order window |
|---|---|---|---|---|
| Initial ShipMonk breach notice | Aug 13, 2026 | ~13,689 | Full: name, email, phone, address (11,742) + partial (1,947) | ShipMonk retention period only |
| Expanded ShipMonk disclosure | Sep 4, 2026 | ~67,000 | Full: name, email, phone, shipping address, order number | Nov 2019 – Aug 2021 |
| Cumulative US impact | Sep 4, 2026 | ~80,689 | Same fields, no private keys | Through Aug 2021 |
The unusual part
ShipMonk kept the data after certifying in writing that it had been deleted
Trezor's Sep 4 statement added a detail that turns a routine vendor breach into something more pointed: the company said it had \"repeatedly requested and received written assurance confirming the deletion of the data\" from ShipMonk, and that it was \"very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.\" In other words, Trezor thought it had a documented data-minimization outcome; the records lived on regardless, and the Sep 2 update to the breach scope only surfaced because ShipMonk's own forensic review found the older cache. Unchained's report on the disclosure framed the gap as the central issue — a vendor that holds personal data under contract and then declines to honor the deletion it certified in writing leaves the wallet vendor, not itself, holding the customer-facing liability.
For Trezor's US exposure, that liability is real even though no funds moved. The leaked dataset pairs home addresses with a confirmed crypto-hardware-wallet purchase, which is exactly the targeting list that physical attackers already use — see Chainalysis's Aug 6, 2026 wrench-attack report, which put2025 violent crypto theft at a record $58M and counted 46 incidents through mid-2026, up from 40 a year earlier. The data-minimization failure isn't a compliance footnote; it's the mechanism that turns a third-party vendor relationship into a downstream physical-safety risk for the wallet buyer.
The regulatory gap
CFTC and SEC have opened doors for self-custody — neither has set data-security rules
Trezor (SatoshiLabs) and Ledger — both private companies headquartered outside the US — sell hardware wallets marketed as non-custodial products, meaning the device maker does not hold customer funds, does not register as a money services business in the traditional sense, and historically argues it is not the entity the SEC or CFTC oversees. That positioning sits at the heart of the \"not your keys, not your coins\" argument and is exactly what US regulators have spent the last twelve months trying to preserve. On Mar 17, 2026 the CFTC's Market Participants Division issued its first no-action letter to Phantom Technologies, letting the self-custodial wallet operator route its users into CFTC-regulated derivatives without registering as an introducing broker. The SEC followed in April 2026 with a staff statement clarifying that non-custodial wallet providers can earn transaction-based fees without broker-dealer registration, then on Aug 18, 2026 proposed \"Regulation Crypto Assets\" — a bespoke offering regime whose investment-contract safe harbor explicitly preserves non-security crypto assets' non-custodial status.
None of those actions touches the data-security surface that the Trezor disclosure now exposes. The CFTC letter, the SEC April staff statement, and the proposed Regulation Crypto Assets framework all proceed from the same premise: the wallet vendor does not custody funds, so the strict broker-dealer and qualified-custody regimes do not apply. What they leave unaddressed is the corollary — when the wallet vendor's order-fulfillment vendor leaks80,000-plus home addresses, what supervisory authority steps in? The SEC's August proposal does not amend Reg S-P for crypto. The CFTC's no-action framework is forward-looking derivatives access, not retroactive data handling. That gap, more than the 67,000-customer number itself, is what reframes the self-custody debate for US-listed names: regulated rails can now plausibly argue that the data-protection burden is part of the cost of being a regulated venue, and that the burden is currently unpriced for the non-custodial alternative.
The physical-safety angle
Address leaks hit a market where wrench attacks are already running at record pace
The leaked fields from Trezor's ShipMonk breach — full name, home address, phone, email, order timestamp — are the exact data profile that crypto-physical-attack analysts say criminal networks already collect manually. The Chainalysis wrench-attack dataset shows 2025 violent crypto theft peaking at $58M, the highest annual figure on record, with 46 documented violent incidents globally through late June 2026 versus 40 at the same point in 2025. Attackers' success rate is dropping — 26% of attempts resulted in a transfer through mid-2026, down from 49% in 2025 — but the absolute incident count is rising, and home invasions are climbing back as the dominant method (37% of attacks in mid-2026, up from 14% in 2025), with kidnappings at 52%.
Chainalysis: violent crypto attacks by year and method
Documented global incidents and the share held by home invasions — rising through mid-2026 even as per-incident success rate falls
Unit: incidents / percent
Incidents 2024 (full year)
48
Incidents 2025 (full year)
95
Incidents mid-2026
46
Home invasion share, mid-2026
% of attacks
37
Kidnapping share, mid-2026
% of attacks
52
An address list tied to a confirmed hardware-wallet purchase is, in the language of these attackers, a pre-qualified target list. That is the part of the disclosure that doesn't show up in any headline about non-custody versus custody — and the part that argues for closer scrutiny of the data-handling chain around any wallet vendor, custodial or not. For investors, the relevant question is whether the gap now becomes a basis for the next US regulatory move: either an SEC or FTC clarification that data-protection obligations attach to wallet vendors regardless of custody status, or a legislative fill-in (a \"CLARITY Act\"–style provision) that names data-security duties for non-custodial providers by statute.
Listed-name impact
Custodial rails look defensive; non-custody-adjacent fintechs do not — and the gap is the trade
The cleanest read on this disclosure is that it strengthens the case for regulated US venues and weakens the pure self-custody narrative for retail buyers — but the listed-name map is not uniform. Coinbase is the most direct beneficiary on the custodial side: Q2 FY2026 results reported Jul 30, 2026 showed $1.22B in revenue and a $359M net loss, with transaction revenue of $599M and subscription & services revenue of $555M (48% of net revenue). Subscription & services, which includes custody and on-chain product revenue, has scaled from $6M in Q2 2020 to $555M in Q2 2026 — the recurring-revenue line that is least sensitive to spot-volume swings. Each new disclosure of a self-custody failure reinforces that flywheel at the margin, because custody revenue grows when retail and institutional clients who do not want to manage a hardware device (or its shipping vendor) route through a regulated venue instead. Coinbase is also the one US-listed venue that already operates its own non-custodial Coinbase Wallet, giving it an unusual dual exposure: if the SEC eventually extends data-security obligations to non-custodial wallet vendors, Coinbase's wallet is already inside a regulated parent.
Robinhood, Block (formerly SQ), and PayPal sit a step further from the breach but in the same defensive basket. Robinhood's Q2 FY2026 trading volume and crypto notional grew, with TTM revenue at $4.93B and net margin of 49.8% per the company's overview — meaning crypto custody via the in-app wallet is a smaller share of revenue but a high-margin line that benefits from any retail rotation away from self-custody. Block's Cash App has built a custodial Bitcoin experience for US consumers since 2018, and PayPal's crypto and PYUSD stablecoin rails put it in the same row of the table. None of these three needs to win market share for the trade to work — they need the average retail wallet buyer to keep concluding that the operational cost of self-custody is too high relative to a regulated venue's fee schedule.
Strategy (formerly MicroStrategy) sits on the other side of the trade: a pure-play on Bitcoin held in custodial venues, with the equity effectively a leveraged proxy for BTC price. The Trezor/ShipMonk disclosure doesn't change the bitcoin holdings themselves (private keys are not on ShipMonk's servers), but a sustained reputational hit to self-custody hardware would, at the margin, increase the share of BTC held in regulated venues — supportive of MSTR's structural premise that institutional and corporate buyers will continue to hold via qualified custodians.
| Ticker | Market cap | Q2 FY2026 revenue | Crypto / wallet exposure | Direction |
|---|---|---|---|---|
| Coinbase | $48.6B | $1.22B (loss $359M) | Exchange + Coinbase Wallet (custodial and self-custody) | Defensive / bullish |
| Robinhood | $112.1B | TTM revenue $4.93B | In-app crypto trading + custody | Defensive / bullish |
| Block | $49.6B | TTM revenue $25.0B | Cash App Bitcoin + Cash App | Defensive / bullish |
| Strategy | $47.0B | TTM revenue $498M | Largest corporate Bitcoin treasury | Indirect / bullish |
| PayPal | $48.6B | TTM revenue $34.1B | Crypto buy/sell + PYUSD stablecoin | Indirect / bullish |
| STMicroelectronics | $46.6B | TTM revenue $13.1B | STM32 / secure-element chips for hardware wallets | Structural / bullish |
| Microchip Technology | $40.2B | TTM revenue $5.12B | MCUs and secure elements for hardware wallets | Structural / bullish |
The supply chain
Chip suppliers to Trezor and Ledger capture the growth either way
The hardware-wallet market that Trezor, Ledger, BitBox, and NGRAVE compete in is still a small corner of the crypto stack, but it is one of the few with a clean double-digit forecast. Mordor Intelligence's July 2026 forecast puts the global hardware-wallet market at $0.54B in 2025, $0.72B in 2026, and $2.25B by 2031 — a roughly 25% CAGR that holds whether the buyer ends up on Trezor's balance sheet, on Ledger's, or on the open-source alternatives. That growth flows back to two publicly traded semiconductor suppliers who ship the secure microcontrollers that go inside the devices.
Global hardware-wallet market, 2025–2031
Forecast values per Mordor Intelligence, Jul 29, 2026
Unit: USD millions
2025 actual
$M
540
2026E
$M
720
2031E
$M
2,250
STMicroelectronics is the more exposed of the two. Trezor's older Model One and Model T ran on ST's STM32F2 and STM32F4 microcontrollers respectively, and the Trezor Safe 5 launched in 2024 around an STM32U5 — the same family of secure MCUs that ST also sells to industrial customers. Ledger pairs ST's ST33 secure element, certified to Common Criteria EAL5+, with a separate general-purpose MCU. Whether the wallet buyer ends up choosing Trezor (STM32-family) or Ledger (ST33 + external MCU), STMicroelectronics still ships the silicon. Microchip Technology sits on a parallel lane: its PIC and SAM microcontrollers are not in the headline SKUs, but its secure-element and MCU catalog is in adjacent devices and in the upstream supply of secure boot and authentication chips. Both names get the same secular tailwind regardless of which brand wins retail wallet share.
What's next
Two horizons: short-term sentiment shifts and the long-term regulatory fill-in
The short-term window (days to quarters) is sentiment and substitution. Each disclosed victim is a target of spear-phishing, SIM-swap attempts, and potential physical targeting, which means the next two quarters will see hardware-wallet vendors competing on shipping-vendor due-diligence and on-chain privacy features rather than on coin-count or screen size. Listed custodial venues (Coinbase, Robinhood, Block) get a defensive bid from retail buyers who re-evaluate the operational cost of self-custody, and chip suppliers (STMicroelectronics, Microchip Technology) get a structural bid from the still-rising wallet market regardless of who wins the brand competition.
The long-term window (one to three years) is the regulatory fill-in. The CFTC's Mar 17, 2026 no-action letter to Phantom and the SEC's Apr 2026 broker-dealer staff statement and Aug 18, 2026 Regulation Crypto Assets proposal together codify that non-custodial wallet vendors are not the entities the agencies oversee — but none of those documents addresses what happens when a non-custody vendor's logistics partner leaks 80,000 home addresses. The Trezor/ShipMonk case is the cleanest US-facing test case the agencies have: a non-custodial device vendor whose third-party vendor failed to honor a written deletion confirmation, exposing data on US residents who self-custody. Expect either an SEC, CFTC, or FTC clarification that data-security obligations attach to wallet vendors by virtue of being data brokers (rather than financial intermediaries), or a congressional fill-in. Until that lands, the structural trade is unchanged — chip suppliers up, regulated rails defensive — but the dispersion across self-custody-adjacent names widens.
Investable names with evidence-backed read-throughs
- Q2 FY2026 subscription & services revenue hit $555M, 48% of net revenue and up from $6M in Q2 2020 — the recurring-revenue line that grows when retail self-custody demand softens after each non-custody failure.
- Coinbase already operates a regulated non-custodial Coinbase Wallet inside a regulated parent, positioning it for any SEC/FTC data-security rule aimed at wallet vendors in the next 12–24 months.
- Q2 FY2026 revenue of $1.22B and $359M net loss show that the transaction side is still volume-cyclical; the defensive read here is on subscription & services, not on quarterly transaction spikes.
- TTM revenue of $4.93B and49.8% net margin reflect an in-app crypto experience that keeps custody and onboarding inside a regulated US broker-dealer — the simplest substitute for a hardware-wallet purchase after a non-custody failure.
- Crypto is a smaller share of revenue than equities and options, so the read-through is more about customer retention than quarter-on-quarter crypto volume.
- Forward P/E near 38x and price-to-sales around 19.5x limit margin for disappointment, but the structural tilt from a Trezor-style disclosure favors regulated rails.
- Cash App Bitcoin has been a custodial US Bitcoin on-ramp since 2018 — positioned to absorb retail flow that steps back from hardware wallets in the wake of the ShipMonk disclosure.
- TTM revenue of $25.0B at a 1.4% net margin reflects Square's payment-rail mix; Bitcoin contribution is small but high-incremental-margin.
- Trade is a sentiment read on retail self-custody substitution, not a direct P&L move — expect the linkage to show up first in user surveys and Cash App inflows.
- Strategy holds its Bitcoin via qualified custodians, not via hardware wallets — each self-custody failure reinforces the institutional case for holding BTC through regulated venues.
- Equity trades as a leveraged proxy on BTC, so the read-through is indirect: any move that shifts BTC custody share toward regulated venues supports the structural premise.
- Operating margin of -68% and EPS of -$116.57 reflect the leverage; size positions to absorb BTC volatility independent of any sentiment tailwind.
- PYUSD stablecoin and the in-app BTC/ETH buy/sell experience put PayPal in the regulated-rail basket — supports the trade but on a smaller revenue contribution than at Coinbase or Robinhood.
- P/E near 9.9x and price-to-sales around 1.4x leave room for multiple expansion, but crypto is not the dominant driver of the multiple.
- Mixed because the structural upside is diluted by PayPal's broader merchant-processing and credit-business overhangs unrelated to the wallet story.
- Trezor Safe 5 runs on ST's STM32U5 and Trezor Model T on the STM32F4; Ledger pairs ST's ST33 secure element — ST ships the silicon regardless of which brand wins the wallet market.
- Global hardware-wallet market is forecast to grow from $0.54B in 2025 to $2.25B by 2031 per Mordor Intelligence, Jul 29, 2026, a roughly 25% CAGR.
- TTM revenue of $13.1B and EV/sales of about 3.2x mean the wallet opportunity is small relative to ST's industrial and automotive book; the thesis is incremental, not transformative.
- Microchip's secure-element and MCU catalog is adjacent to the wallet supply chain via secure boot, authentication, and select MCU sockets — captures the structural bid on wallet shipments without needing to be the primary MCU.
- TTM revenue of $5.12B and forward P/E near 19.3x leave room for incremental wallet-driven upside to be additive rather than transformational.
- Trade is more about incremental wallet-share upside than about a single brand's customer breach; expect a multi-quarter lift rather than a quarter-on-quarter spike.
