
Exposed customers face phishing and physical risks from the ShipMonk breach. Violent crypto thefts topped $30M in H1 2026, on pace to exceed 2025.
Hardware wallet maker Trezor said a breach at ShipMonk, the third-party fulfillment provider that stores and ships its products in several markets, exposed personal information belonging to 13,689 customers. The company said its own systems were not compromised, and customers' devices and private keys remain secure.
ShipMonk informed Trezor on Monday, Aug. 10 that an unauthorized actor had accessed systems holding customer order data.
Trezor published a disclosure Thursday, Aug. 13.
The breach is the first since Trezor's 2013 founding to expose customer phone numbers and shipping addresses, the company said. Of the affected customers, 11,742 had full exposure covering name, phone number, email address and shipping address; an estimated 1,947 had their name and email exposed along with city.
Trezor said affected orders were received between May 10 and Aug. 8 across the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal. Every affected customer was emailed directly, and anyone who did not receive a notice was not caught in the breach, the company said. Exposed customers should expect more sophisticated phishing attempts from attackers impersonating Trezor or other financial institutions, the company warned.
Phishing is not the only risk. Physical attacks on crypto holders are rising, and a Ledger co-founder was kidnapped in France. Chainalysis data shows more than $30 million was stolen in violent crypto attacks during the first half of 2026, putting the year on pace to exceed 2025's full-year total of $58 million.
Rival Ledger has faced both risks before. A 2020 breach exposed data on more than 270,000 customers, and names, emails, phone numbers and some home addresses were later posted to a hacking forum. The posted records produced years of phishing calls and physical scam letters demanding seed phrases. In January, Ledger customers were notified of another exposure, this time through e-commerce provider Global-e.
Trezor said the scale of the incident was limited by a 90-day retention policy that it also requires of fulfillment partners, meaning older order data had already been deleted or anonymized. The company also pointed to an Anonymous Delivery option using locker pickup and neutral packaging, with automatic deletion of shipping identifiers. It aims to launch the option in the EU by September 2026 and in the U.S. by year-end.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.