
13,689 Trezor customers had names, phone numbers and shipping addresses stolen from logistics partner ShipMonk. No funds at risk; physical targeting is the real threat. The stolen data set is a verified list of hardware wallet owners with delivery addresses.
Trezor confirmed on Aug. 13 that a shipping provider data breach exposed the personal order details of 13,689 hardware wallet buyers. No private keys were touched. No device was compromised. The leaked data set is a verified list of people who own a hardware wallet, complete with the delivery address.
Logistics partner ShipMonk told Trezor on Aug. 10 that an unauthorized actor accessed systems containing customer order data. ShipMonk holds the recipient name, shipping address, phone number, email address and order number to deliver parcels in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. That exact data set was exposed.
Trezor published a breakdown. The breach covers customers who received an order between May 10 and Aug. 8, 2026, in those seven countries. Trezor enforces a 90-day data retention policy and contractually requires fulfilment partners to delete or anonymize order data 90 days after delivery. That policy limited the exposure to roughly 13,700 people rather than every buyer in the company's history.
Trezor emailed every exposed customer directly from help@trezor.io. If that email is not in your inbox, you are not on the list. Scammers will impersonate that notification in the coming days.
No wallet compromise
This is a supply chain breach, not a wallet breach. Trezor's own systems were not compromised. No private keys, wallet backups, seed phrases or firmware were involved. No funds are at risk from the incident itself. The weak point was the commercial layer around the product.
The technical distinction matters. In practice, attackers now hold infrastructure-grade targeting data: a fresh list of confirmed crypto holders matched to real home addresses and phone numbers. An email leak is a nuisance. A name plus a home address plus a phone number identifies a specific person at a specific door as someone who likely holds cryptocurrency.
Trezor confirmed this is the first breach since the company was founded in 2013 to expose customer phone numbers and shipping addresses. A separate January 2024 incident at a third-party support portal exposed contact details of nearly 66,000 users, though not physical addresses.
The Ledger precedent
The crypto industry already has a playbook. When roughly 272,000 Ledger customer records including names, addresses and phone numbers were published following that company’s 2020 e-commerce breach, the fallout never really ended. Victims reported waves of phishing emails and SMS, counterfeit hardware wallets mailed to their homes in 2021, physical letters with malicious QR codes, and phone calls from people who spoke as though they knew them personally. Some received ransom demands with threats of violence.
CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier. Home invasions overtook kidnapping as the most common method. Chainalysis put the amount stolen through violent attacks at more than $30 million over the same period, on pace to pass 2025’s full-year total of roughly $58 million.
Vendors keep proving to be the weakest link. Ledger’s payment processor Global-e leaked customer order data in January 2026. Within days, attackers sent phishing emails announcing a fake Ledger and Trezor merger, personalized with the leaked order details. ShipMonk holds SOC 2 Type II certification, an audited security standard, and was breached regardless.
Trezor’s guidance is short, and the industry track record says it works. Trezor tells customers to ignore any unsolicited contact that references their purchase. The company never calls customers. It never sends hardware through third parties. It never asks for a seed phrase. Anyone who receives a message with a link should visit trezor.io directly. Entering a recovery seed into a computer, phone or website is never necessary. The only place the seed belongs is the hardware device itself. Anyone who wants to check status or raise a concern can contact Trezor support through the official site.
Trezor says it is accelerating an Anonymous Delivery option designed to break the link between a hardware wallet purchase and a real-world identity. Under the planned system, orders would use a randomized shipping label format that replaces the customer name with a code and strips the return address to a generic Trezor distribution center. Trezor targets availability in the EU by September 2026 and in the US by the end of 2026. The company describes the project as a top priority. In the meantime, Trezor suggests ordering with an email address not linked to your real identity, paying with crypto or a disposable virtual card, and using a P.O. Box where practical.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.