
Nearly 14,000 Trezor customers had names, emails, phone numbers and addresses stolen after a hack of shipping partner ShipMonk. The risk of phishing and physical theft rises.
Alpha Score of 52 reflects moderate overall profile with strong momentum, weak value, moderate sentiment. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
Nearly 14,000 Trezor buyers had their names, email addresses, phone numbers, and shipping addresses stolen after ShipMonk, the hardware wallet maker's fulfillment partner, suffered a data breach. The attack puts affected customers at greater risk of phishing attempts and, in some cases, theft at their homes. French users have already reported such incidents, Trezor said.
ShipMonk disclosed the breach on Monday, August 10. Orders shipped between May 10 and August 8 were exposed. Trezor's own infrastructure was not touched; the wallets themselves remain secure. Of the 13,689 victims, 11,742 had their full contact information taken. The remaining 1,947 lost only their names, cities, and email addresses. The affected buyers span seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
Damage was partly limited because ShipMonk deletes or anonymizes order records three months after delivery. Customers who bought through Amazon were spared, Trezor said, because those orders moved through a different fulfillment channel.
The attackers exploited a critical SQL injection zero-day in Metabase, an analytics platform ShipMonk uses. Metabase publicly flagged the vulnerability on August 6. The same campaign hit laptop maker Framework and form builder Tally. ShipMonk has since received extortionary emails from the ShinyHunters group, Trezor said. There is no evidence so far that the stolen data has been published, sold, or used in any scam.
This is not Trezor's first such incident. A breach of its third-party support portal in January 2024 affected about 66,000 users. Another event in 2022 exposed more than 106,000 customers. But this is the first attack to leak customer phone numbers and shipping addresses, Trezor said.
Trezor's main rival, Ledger, also has a history of data leaks. A 2020 breach spilled data on hundreds of thousands of users. As recently as May 2026, scammers mailed Ledger owners fake "Quantum Resistance Security Update" letters with malicious QR codes, using data from a separate leak through payment processor Global-e in January.
The broader trend is worrying. Criminals are using leaked personal data to target crypto holders for kidnappings and home invasions, forcing victims to surrender their crypto. Chainalysis reported that more than $30 million was taken in violent attacks in the first half of 2026, a pace that would surpass 2025's full-year figure of $58 million.
The breach highlights supply-chain risks for crypto hardware wallet users. Trezor said it notified affected customers by email. The company is developing a more private shipping option with lockers, neutral packaging, and automatic deletion of address data after delivery. That service is planned to launch in the EU by September and in the U.S. by the end of the year.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.