Key facts
- A data breach at Trezor's shipping partner, ShipMonk, exposed personal data of 13,689 customers.
- Exposed data includes full names, phone numbers, email addresses, and shipping addresses for a subset of affected customers.
- Trezor's own systems and customer wallet data remained secure.
- Affected customers placed orders between May 10 and August 8 and had them shipped to specific countries.
- Trezor is accelerating the rollout of an Anonymous Delivery option.
A data breach at ShipMonk, a fulfillment partner for hardware wallet manufacturer Trezor, has exposed the personal information of 13,689 customers. The breach, disclosed by Trezor on Thursday, involved unauthorized access to systems holding customer data. Specifically, 11,742 customers had their full names, phone numbers, email addresses, and shipping addresses compromised, while an additional 1,947 customers had their names, cities, and email addresses exposed. These customers placed orders between May 10 and August 8 and their shipments were destined for the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal.
Trezor emphasized that its own internal systems were not breached and that no device, private key, or wallet backup information was affected. The company attributed this limited scope to its policy requiring partners to delete or anonymize order data 90 days after delivery. Customers who have not received a notification email are not impacted. This incident marks the first time in Trezor's 13-year history that customer phone numbers and shipping addresses have been exposed.
The company is advising customers to be vigilant against phishing attempts and to never enter wallet backups online. The incident echoes a 2020 breach at rival Ledger, where customer data was published, leading to subsequent threats and phishing attacks. Recent data indicates a rise in physical attacks on crypto holders, with significant amounts stolen in the first half of 2026. Trezor is also accelerating the introduction of an Anonymous Delivery option, featuring locker pickup, neutral packaging, and generic sender details, with plans for EU rollout by September and US availability by year-end.
