Summary
- A breach at ShipMonk, a fulfillment partner for Trezor, has compromised personal information for 13,689 customers.
- Of these, 11,742 had their full names, phone numbers, emails, and shipping addresses exposed.
- Trezor confirmed that no devices, private keys, or wallet backups were impacted, and their own systems remained secure.
A data breach involving ShipMonk, one of Trezor's shipping partners, has led to the exposure of sensitive information, including names, phone numbers, email addresses, and residential addresses of thousands of Trezor customers, as reported by the company on Thursday.
ShipMonk notified Trezor on Monday about the unauthorized access to systems containing customer information. A total of 11,742 customers had their complete details compromised, while an additional 1,947 experienced exposure of names, cities, and email addresses, bringing the total to 13,689 affected individuals. These customers placed orders between May 10 and August 8, with shipments directed to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
Trezor assured users that its systems were not breached and that no devices, private keys, or wallet backups were compromised. The company noted that its data retention policy requires partners to delete or anonymize order data after 90 days of delivery, which limited the scope of the breach. Customers who did not receive a notification email are not considered at risk, according to Trezor. The company emphasized that in its 13 years of operation, it had never previously experienced a breach exposing customer phone numbers or shipping addresses.
Phishing and Security Risks
In light of the breach, Trezor has issued warnings about potential phishing attempts, advising customers to be cautious of unexpected communications and to refrain from entering wallet backups online. The situation echoes a prior incident with rival Ledger, which indicates that the risk may extend beyond just fraudulent emails.
After a significant breach exposed personal information of around 272,000 Ledger customers, some reported receiving ransom threats, including violent demands. One individual shared with Decrypt that they were inundated with multiple threatening emails and texts daily, while others reported receiving phishing calls from individuals who seemed familiar with them.
This year has seen a rise in physical attacks targeting cryptocurrency holders, with CertiK confirming 52 incidents globally in the first half of 2026, an increase from 39 the previous year. Home invasions have now surpassed kidnappings as the most common method of attack, with Chainalysis reporting over $30 million stolen during this timeframe, indicating that 2026 could be the worst year on record for such crimes.
This incident is not isolated within the hardware wallet supply chain; Ledger previously reported a breach involving its e-commerce partner, Global-e, in January. Additionally, hardware wallet companies have recently issued warnings about a surge in phishing attempts, with losses from the Coldcard exploit nearing $130 million.
The news comes on the heels of a significant exploit impacting hardware wallet users. A portion of the 233,000 BTC, valued at about $15 billion, that was moved from long-term wallets due to the Coldcard breach, originated from Ledger and Trezor users who opted for multi-signature setups after the incident, as reported by Casa.
In response to the breach, Trezor is expediting the introduction of an Anonymous Delivery option, which will feature locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers, targeting the European Union by September and the United States by year’s end.
