
A ShipMonk breach exposed names, addresses, and phone numbers of 13,689 Trezor customers. No wallet compromise, but phishing risk is high. Trezor plans Anonymous Delivery.
Hardware crypto wallet company Trezor warned Thursday of heightened phishing risk after a breach at third-party logistics provider ShipMonk exposed personal information belonging to 13,689 customers.
The leaked data includes names, addresses, phone numbers and email addresses. Of the affected customers, 11,742 had full names, email addresses, phone numbers and shipping addresses exposed. The remaining 1,947 customers had partial data exposed, including names and email addresses.
ShipMonk notified Trezor on August 10 that an unauthorized actor had accessed systems containing customer data. ShipMonk provides logistics services for Trezor, including storing and shipping its products in several markets. The affected records primarily involved new-customer orders placed between May 10 and August 8, 2026, and shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor said there was no evidence that wallet backups, cryptocurrency holdings, or its own systems were compromised. The company cautioned that the leaked data could be used to craft more convincing scams targeting affected users.
Trezor said its 90-day data-retention policy with logistics partners helped limit the scope of the incident because older order information had already been deleted or anonymized. The company is still working with ShipMonk to determine the exact exposure window for the 1,947 customers whose partial information was affected.
Trezor said affected customers were individually notified by email from help@trezor.io. Customers who did not receive a notification are not affected, according to the company.
The main risk from the breach is the personal information that could be used to impersonate Trezor or create more convincing fraudulent messages. Names, phone numbers, email addresses and shipping information can provide attackers with additional context for targeted phishing campaigns. A message that references a customer's name, recent Trezor purchase or delivery details may appear more credible than a generic scam. Attackers could then attempt to persuade victims to disclose sensitive information, click malicious links or reveal their wallet backup.
Trezor described the incident as the first breach since its founding in 2013 to expose customer phone numbers and shipping addresses and apologized to affected users.
The company plans to introduce an Anonymous Delivery option featuring dedicated checkout, locker pickup, neutral packaging and automatic deletion of shipping identifiers. Trezor aims to launch the service in the EU by September 2026 and in the US by the end of 2026.
The ShipMonk incident follows earlier security problems involving third-party providers. In January 2024, unauthorized access to Trezor's third-party support portal potentially exposed names and email addresses of about 66,000 users. A separate Mailchimp breach in 2022 affected Trezor customers and was followed by phishing campaigns targeting cryptocurrency users.
Other hardware-wallet companies have faced similar incidents. Ledger, for example, suffered a major 2020 data breach that exposed more than 1 million email addresses and hundreds of thousands of customer records. Some of that information was subsequently used in cryptocurrency scams.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.