Advertisement

Trezor Shipping-Provider Breach Exposes Data of 13,689 Customers

ShipMonk incident exposed names and contact details of recent customers in seven countries; Trezor says its devices and systems were not compromised.
Trezor Shipping-Provider Breach Exposes Data of 13,689 Customers

Trezor said a breach at third-party shipping provider ShipMonk exposed personal and order data belonging to 13,689 recent customers, including names and contact details that can be used for targeted phishing. Shipping addresses also create a potential physical-security risk by tying named customers to recent Trezor orders.

In its disclosure, Trezor said 11,742 customers had their full name, email address, phone number and shipping address exposed. Another 1,947 had their name, city and email address exposed.

The affected orders were delivered between May 10 and Aug. 8 to customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal. Trezor said ShipMonk informed it on Aug. 10 of unauthorized access to systems containing customer data. The investigation remains ongoing.

Trezor said its own systems were not compromised and that its devices remain secure. All affected customers were contacted separately by email, according to the company; its notice says customers who did not receive an email from help@trezor.io were not affected.

The company warned recipients to expect more sophisticated phishing attempts and said scammers could use the information for fake emails, phone calls and letters, or to impersonate Trezor, a bank or a crypto exchange. It told customers never to enter their wallet backup on a website or share it with anyone, and to verify messages against Trezor's official channels.

Physical-Security Risk

The exposed records identify people who recently received an order from Trezor and, for most of those affected, include the address where it was delivered. That combination can make a fake support message more convincing and could also help a criminal select a physical target.

A public repository maintained by Jameson Lopp lists known physical attacks against bitcoin and crypto owners dating back to 2014, including home invasions, kidnappings, robberies and extortion. Trezor's disclosure describes a potential risk; it did not report a compromise of its systems or devices.

Retention Policy Limited the Exposure

Trezor attributed the scope of the breach to a 90-day data-retention policy that also applies to its fulfillment partners. Its published privacy policy says names, addresses, phone numbers and emails used for delivery are deleted from Trezor and fulfillment-partner systems after 90 days, subject to exceptions for unresolved order issues.

The company said this was the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses. Trezor aims to make an “Anonymous Delivery” option available in the European Union by September 2026 and in the U.S. by the end of 2026. The proposed feature includes locker pickup and automatic deletion of shipping identifiers after delivery.

Order-data exposure has repeatedly affected customers of hardware-wallet companies without necessarily compromising the wallets themselves. Ledger said a January 2026 incident at commerce provider Global-e exposed names, postal addresses, email addresses, phone numbers and order details, while leaving Ledger devices and systems unaffected.

Ledger also disclosed in 2020 that an unauthorized party accessed its ecommerce and marketing database, exposing email addresses and, for a subset of customers, names, postal addresses, phone numbers and order information.

Trezor said ShipMonk has secured and hardened the affected systems while the companies work to establish exactly what happened and which data was accessed.

Advertisement

Get an edge in Crypto with our free daily newsletter

Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri

90k+ Defiers informed every day. Unsubscribe anytime.