
Trezor disclosed a breach at shipping partner ShipMonk, exposing names, emails, and addresses for roughly 13,700 recent customers. The leak links identities to hardware wallet owners, raising phishing risks. Trezor plans an Anonymous Delivery option by September.
A Trezor data breach at shipping partner ShipMonk has exposed personal information tied to about 13,700 recent customers. Names, email addresses, phone numbers, and physical addresses were accessed by an unauthorized party, the hardware wallet maker confirmed.
The exposure covers orders placed between May 10 and August 8, 2026. Trezor said its internal systems and private keys were not touched. The company has begun notifying affected users and published guidance on avoiding phishing attempts.
ShipMonk informed Trezor on August 10 that unauthorized access had occurred within its order systems. Customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were included. Trezor said the breach was limited to fulfillment data, not wallet security.
Of those affected, 11,742 customers had full details exposed: name, email, phone number, and address. Another 1,947 had partial exposure limited to name, city, and email. Trezor credited its 90-day retention policy with limiting the scope. Older order records had already been deleted from ShipMonk systems before the breach.
Trezor called the event the first breach since its 2013 founding to expose phone numbers and shipping addresses. The company said it understands how serious the situation is, acknowledging the risk to affected customers. Support channels remain open.
Binance co-founder Changpeng Zhao commented on the incident, noting hardware wallets are generally seen as more secure than software options. He said the breach shows an advantage of software self-custody tools, which skip shipping a device tied to identity. Zhao added, “Not saying hardware wallets are ‘bad’. Just different risk profiles.”
Trezor urged affected customers to treat unexpected emails, calls, or letters with caution. The company recommended checking any communication against its official blog and social channels before responding. Customers were reminded never to enter a wallet recovery phrase online or share it with anyone.
Trezor outlined steps buyers can take to reduce data exposure on future orders: use an email address not linked to a real identity, pay with crypto or disposable cards, or use a P.O. Box. The company also announced an upcoming Anonymous Delivery option built to reduce identity exposure during shipping. The feature uses a dedicated checkout, locker pickup, and neutral packaging with no visible sender name. Trezor plans to launch the option in the European Union by September 2026 and in the United States by year-end.
Trezor reiterated that no company systems, products, or services were affected by the ShipMonk breach. Devices already in customers' hands remain secure, and private keys were never exposed. The main risk going forward, Trezor said, is an increase in targeted phishing attempts.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.