All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Trezor Customer Data Exposed in Shipping Partner Breach

Created at 13 Aug · 1:17 PM1 source↑ Market-relevant
IN SHORT

A data breach at Trezor's fulfillment partner, ShipMonk, exposed personal data of 13,689 customers, including names, emails, and shipping addresses. Trezor stated its own systems were not compromised and no wallet data was affected.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

13,689Trezor customers affected by data breach
11,742Customers with full details taken
1,947Customers with names, cities, and emails exposed
90 daysData retention policy for partners
13 yearsTrezor's history without phone/address breach
52Physical attacks on crypto holders in H1 2026
$30 millionStolen in crypto attacks in H1 2026

Who's Involved

ShipMonk
Trezor's fulfillment partner experiencing a data breach
Trezor
Hardware wallet manufacturer disclosing customer data exposure
Ledger
Rival hardware wallet company with a past data breach
CertiK
Security firm verifying physical attacks on crypto holders
Chainalysis
Firm reporting on crypto theft amounts
Global-e
Ledger's e-commerce partner that experienced a breach
Coldcard
Hardware wallet firm associated with a recent exploit
Casa
Firm providing analysis on Coldcard breach impact
Trezor Customer Data Exposed in Shipping Partner Breach

↳ Why This Matters

This breach highlights the security risks associated with third-party vendors in the hardware wallet supply chain, potentially exposing users to phishing and other targeted attacks, despite the core device security remaining intact.

Key facts

  • A data breach at Trezor's shipping partner, ShipMonk, exposed personal data of 13,689 customers.
  • Exposed data includes full names, phone numbers, email addresses, and shipping addresses for a subset of affected customers.
  • Trezor's own systems and customer wallet data remained secure.
  • Affected customers placed orders between May 10 and August 8 and had them shipped to specific countries.
  • Trezor is accelerating the rollout of an Anonymous Delivery option.

A data breach at ShipMonk, a fulfillment partner for hardware wallet manufacturer Trezor, has exposed the personal information of 13,689 customers. The breach, disclosed by Trezor on Thursday, involved unauthorized access to systems holding customer data. Specifically, 11,742 customers had their full names, phone numbers, email addresses, and shipping addresses compromised, while an additional 1,947 customers had their names, cities, and email addresses exposed. These customers placed orders between May 10 and August 8 and their shipments were destined for the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal.

Trezor emphasized that its own internal systems were not breached and that no device, private key, or wallet backup information was affected. The company attributed this limited scope to its policy requiring partners to delete or anonymize order data 90 days after delivery. Customers who have not received a notification email are not impacted. This incident marks the first time in Trezor's 13-year history that customer phone numbers and shipping addresses have been exposed.

The company is advising customers to be vigilant against phishing attempts and to never enter wallet backups online. The incident echoes a 2020 breach at rival Ledger, where customer data was published, leading to subsequent threats and phishing attacks. Recent data indicates a rise in physical attacks on crypto holders, with significant amounts stolen in the first half of 2026. Trezor is also accelerating the introduction of an Anonymous Delivery option, featuring locker pickup, neutral packaging, and generic sender details, with plans for EU rollout by September and US availability by year-end.

Frequently asked questions

Full names, phone numbers, email addresses, and shipping addresses were taken for 11,742 customers. An additional 1,947 customers had names, cities, and email addresses exposed.

No, Trezor stated that its own systems were not compromised, and no device, private key, or wallet backup was affected.

ShipMonk is one of Trezor's fulfillment partners responsible for storing and shipping Trezor's products.

Trezor is accelerating the launch of an Anonymous Delivery option, which includes locker pickup, neutral packaging, and generic sender details.

What Happens Next

01Trezor plans to roll out an Anonymous Delivery option by September in the EU and by the end of the year in the US.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Product Modification Summary: Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether — Effective August 10, 2026
    6 Aug · 7:45 PM

How It Developed

A breach occurred at ShipMonk, a Trezor fulfillment partner.
Personal data of 13,689 Trezor customers was exposed.
Full names, phone numbers, email addresses, and shipping addresses were taken for 11,742 customers.
Names, cities, and email addresses were exposed for an additional 1,947 customers.
Trezor confirmed its own systems were not compromised and no device or private key data was affected.
Trezor is implementing an Anonymous Delivery option for customers.

Sources

T1
Trezor Customer Data Exposed in Shipping Partner BreachDecrypt

Related Stories

Metaplanet CEO denies Bitcoin sale after large transfer
13 Aug · 4:31 AM
Delio CEO Sentenced to 15 Years for $49 Million Crypto Fraud
13 Aug · 10:21 AM
Metaplanet Reports $20M Operating Profit Despite Bitcoin Price Drop
13 Aug · 11:12 AM
BitGo posts $19M Q2 loss despite 80% revenue surge to $4.3B
13 Aug · 7:56 AM
Metaplanet, MicroStrategy unrealized bitcoin losses total $9.7B
13 Aug · 11:42 AM