
Trezor's shipping provider ShipMonk leaked names, emails, addresses of 13,689 customers. No wallet keys exposed, but phishing attacks targeting hardware wallet owners are the main risk. Affected orders from May to Aug in 7 countries.
Data of 13,689 Trezor customers was leaked after an unauthorized access at ShipMonk, a shipping provider the company uses. Trezor said its internal systems, wallets, and devices were not compromised. The danger instead lies in what the exposed information enables: phishing attacks targeting hardware wallet owners.
The stolen records include names, email addresses, phone numbers, and shipping addresses for 11,742 customers. Another 1,947 customers had their names, cities, and email addresses taken. The affected orders were shipped between May 10 and August 8, covering the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
ShipMonk notified Trezor of the breach on August 10. Trezor released a public statement on August 13 and said the investigation is ongoing.
With that information, attackers could impersonate Trezor, a cryptocurrency exchange, or a financial institution through email, phone, or mail. Trezor said the breach is limited because of its 90-day data storage policy. No wallet backups, private keys, or payment data were exposed.
The incident follows a separate vulnerability at Coldcard, a competitor in hardware wallets. Coldcard had a flaw in wallet seed creation. By August 5, attackers had stolen 1,816 BTC – roughly $116 million – through that exploit, according to TRM Labs. The two cases differ: Coldcard involved a direct wallet flaw, while Trezor's breach occurred at a third-party shipping provider and exposed customer identities, not keys.
Hardware wallet owners are frequent targets of social engineering because they may hold significant cryptocurrency. A convincing email or phone call referencing a customer's name and address could trick them into revealing their recovery seed or transferring funds. Trezor's advisory warned users to treat any unsolicited communication claiming to be from the company as suspicious.
Trezor said it has contacted affected customers directly and urged all users to verify any contact through official channels only. The company did not say whether it would change shipping providers or data retention policies as a result of the breach.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.