
A data breach at Trezor logistics partner ShipMonk exposed the personal information of 13,689 hardware wallet customers.
Trezor says its own systems and devices were not compromised, but warned affected customers to expect more convincing phishing attempts.
Trezor disclosed the incident earlier today, three days after ShipMonk notified the company of unauthorized access to systems containing customer order data. The investigation remains ongoing, and Trezor said ShipMonk has secured and hardened the affected systems following the breach.
According to Trezor's incident report, 11,742 customers had their full names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 customers had names, cities, and email addresses accessed, bringing the total number affected to approximately 13,689.
Trezor, founded in 2013, develops hardware cryptocurrency wallets designed to keep private keys isolated from internet-connected devices. ShipMonk is one of its fulfillment and logistics partners, storing products and processing shipments in the United States, United Kingdom, and several other markets. The company requires customer contact information to deliver orders, including details requested by shipping carriers.
The breach potentially affects customers who received Trezor orders between May 10 and August 8, 2026, in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor said all affected users have been contacted from help@trezor.io and that customers who did not receive the notification were not impacted.
The scope was limited by Trezor's 90-day data retention policy, which also applies to its fulfillment partners. Order information is deleted or anonymized after that period, meaning older customer records were no longer stored in ShipMonk's systems when the breach occurred.
No wallet backups, private keys, payment credentials, or data stored on Trezor devices were identified as exposed. However, the leaked contact and address information could enable attackers to create highly targeted social-engineering campaigns.
Attackers could impersonate Trezor, cryptocurrency exchanges, banks, or other trusted organizations through email, phone calls, text messages, or physical mail. Knowledge of a victim's name, address, and connection to a hardware wallet provider could make fraudulent messages significantly more convincing.
Trezor said this is the first incident since its founding in which a breach involving one of its partners exposed customer phone numbers and shipping addresses.
Affected users should treat unexpected messages concerning their cryptocurrency holdings with particular caution. Trezor advises customers to verify communications against its official website and channels, avoid responding to urgent requests for sensitive information, and never disclose or enter their wallet backup or recovery seed on a website.
The company also recommends reducing personal information shared when ordering hardware wallets where practical, such as using separate email addresses or P.O. boxes.
Trezor plans to introduce an “Anonymous Delivery” option using locker pickup, neutral packaging, generic sender information, and post-delivery deletion of shipping identifiers, with an EU launch targeted for September 2026 and US availability planned by the end of the year.







Leave a Reply