
Trezor said a breach at shipping provider Shipmonk exposed personal data of about 13,689 customers. Hardware wallets remain secure, but phishing risk rises. Anonymous Delivery planned for EU by September, US by year-end 2026.
Trezor said a breach at its shipping provider Shipmonk exposed personal order data for about 13,689 recent customers, raising the risk of targeted phishing attacks but not compromising the company's hardware wallets.
The hardware wallet maker said Shipmonk notified it on Aug. 10 of unauthorized access to systems holding customer data. The affected customers placed orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal during the 90 days before Aug. 8, Trezor wrote in a security update.
Trezor said 11,742 customers had their full names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 had partial information exposed: names, cities, and email addresses.
The private keys that control cryptocurrency on a Trezor device were not exposed. "Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts," Trezor said on X.
Phishing is a fraud tactic in which criminals pose as trusted companies to trick people into handing over sensitive information. "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor," the company said in its customer notice.
The risk is especially serious for hardware wallet owners because thieves may try to obtain a wallet backup, also known as a recovery phrase. Anyone who obtains a recovery phrase can restore access to a crypto wallet and take the funds.
Trezor urged customers never to enter a wallet backup on a website or share it with anyone. It advised people to treat messages seeking urgent action or personal information with suspicion and verify communications through official Trezor channels.
Shipmonk is a logistics provider that stores products and sends orders to buyers. Trezor said such a partner needs basic delivery information, including a recipient's name, address, phone number, and email address.
Trezor emphasized that its own systems, products, and services were not compromised. "Trezor devices remain entirely safe and secure," the company said. Normal operations continue.
The company said its 90-day retention policy limited the breach. Trezor requires fulfillment partners to delete or anonymize customer order data 90 days after delivery, once the period needed for delivery, returns, refunds, and replacements has passed.
"The one real impact is that affected customers may see more phishing attempts by email, phone, or post," Trezor disclosed. It said affected customers were contacted directly from help@trezor.io and that people who did not receive that notice were not affected.
The incident is not the first customer-data breach tied to a hardware wallet maker. Ledger, another major manufacturer, suffered a breach involving its e-commerce and marketing database in 2020. That incident exposed roughly 1 million email addresses and later about 272,000 more detailed customer records, including names, postal addresses, phone numbers, and ordered products.
The Ledger episode showed why personal information linked to crypto ownership can be valuable to criminals even when wallet technology itself remains secure. It can help scammers craft believable messages aimed at a known customer.
Trezor said it is working on a more private shipping method. "We are currently working on an Anonymous Delivery option, which we aim to have ready by September for the EU and by the end of the year for the US. This gives you a safer way to order hardware wallets without linking the purchase to your home address or real-world identity."
Trezor further disclosed that Shipmonk has secured and strengthened the affected systems while the investigation continues. Trezor plans to introduce Anonymous Delivery in the European Union by September and in the United States by the end of 2026.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.