
ShipMonk breach leaked Trezor buyers' names, phones, addresses. Affected orders May-Aug 2026. Trezor plans Anonymous Delivery in EU Sept 2026 — a test for hardware wallet privacy.
Hardware wallet maker Trezor disclosed a security incident involving its third-party fulfillment provider ShipMonk. The breach exposed customer order data, including home addresses, for 13,689 people across seven countries. The company said its own systems, hardware wallets, private keys and recovery seeds were not affected.
ShipMonk notified Trezor on August 10 of unauthorized access to the order database. The exposed records cover deliveries between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
For 11,742 customers, the stolen information included full names, phone numbers, email addresses and physical street addresses. Another 1,947 customers had names and email addresses exposed.
Trezor's own infrastructure remained intact. That distinction matters. It does not make the stolen information harmless.
A conventional wallet exploit seeks the credentials needed to move cryptocurrency. The ShipMonk incident creates a different problem. Attackers obtained information that can link real identities to hardware-wallet purchases.
For an ordinary e-commerce company, a leaked address is a privacy problem. For a hardware-wallet manufacturer, the same record can reveal that someone bought a device designed to store cryptocurrency offline. Trezor said affected users should watch for targeted phishing emails, SMS messages and phone calls. The company noted that no legitimate support interaction requires revealing a recovery seed.
This incident is part of a broader pattern. Ledger has previously dealt with customer information exposed through third-party logistics. The underlying lesson is that hardware-wallet security extends beyond the device itself to the commercial infrastructure around it.
One detail limited the scale of the breach. Trezor requires fulfillment partners to permanently delete or anonymize customer order data 90 days after delivery. Older records had already been removed from the environment the unauthorized party accessed. Without that policy, years of historical purchases could have remained available.
The incident also highlights a physical dimension. Security researchers have documented cases involving coercion, robbery and extortion against cryptocurrency holders. There is no evidence that affected Trezor customers are being targeted physically, and purchasing a Trezor does not establish ownership of a large portfolio. Still, a database combining a person's identity, telephone number and residential address with a hardware-wallet purchase provides a more specific targeting signal than an ordinary consumer leak.
Trezor's longer-term response may be more consequential than standard post-breach steps. The company plans to introduce an Anonymous Delivery option in the European Union in September 2026, followed by the United States later in the year. The system includes secure locker pickups and automatic removal of shipping identifiers. Instead of trying to protect a permanent database, that model reduces how much sensitive information exists in the first place.
For the hardware-wallet industry, privacy-preserving fulfillment could become a competitive feature alongside secure elements and firmware architecture. The next test will be adoption rates, actual retention periods, and whether competitors introduce comparable systems.
Read more: crypto market analysis
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.