Start with the threat model. If you have a hardware wallet posted to your home, a courier’s database now holds your legal name, your phone number, your address, and a line item saying you own a hardware wallet. That file is a shopping list for anyone who gets hold of it. It is not a key-compromise risk. It is a doorstep risk.

That is the risk Trezor is now building against. In its disclosure of the ShipMonk shipping-provider breach, first posted 13 August 2026, the company describes an option called Anonymous Delivery: a dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. It aims, in its own words, to make that available in the EU by September 2026 and in the US by the end of 2026.

September has arrived. As of this writing the same page — carrying an update dated 4 September 2026 — still lists the option as “coming soon”. That is a target the company set itself, and it is worth watching rather than scoring.

What the breach actually was

Trezor says ShipMonk informed it of unauthorised access on 10 August 2026, affecting 11,742 customers with full exposure and 1,947 with partial exposure, for orders shipped between 10 May and 8 August 2026 to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. The company states its own systems were not compromised and that devices remain secure.

The 4 September update says Trezor was informed on 2 September that the breach also contained order data from a prior 2019–2021 engagement, affecting approximately another 67,000 US customers with full exposure. Those are separate numbers from separate periods; do not add them together.

Note what failed. Trezor says its contract required deletion after 90 days, that it received written confirmation of deletion, and that the data was not deleted. A retention policy is only as good as the partner honouring it.

What it would and would not fix

Locker pickup and a generic sender label defend against the courier-database leak described above, and against a neighbour or a delivery driver reading a branded box. They do nothing about a phishing email, a tampered device, or a browser session you approved something in. As with the Ledger bulletins where the fix turned out to be an app update, the honest question is always which layer the mitigation sits on.

The seed never leaves the device either way, and the rules do not change with the packaging: your backup is never typed into a keyboard, never photographed, never stored in a cloud, never given to support. If your address was in that file, assume the phone call will be convincing.

Read the company’s page yourself before deciding what to order and how. Crypto assets are high risk, nothing here is financial advice, and the checking is yours to do.