Trezor warned 13,689 customers that their personal information was exposed after an unauthorized actor breached systems belonging to fulfillment provider ShipMonk.
The hardware wallet maker said ShipMonk notified it on Aug. 10 after discovering unauthorized access to systems containing customer order data. Trezor’s own infrastructure, devices and wallet backups were not compromised.
Announcement from Trezor
The incident affected customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Of those affected, 11,742 had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had names, cities and email addresses compromised, although Trezor said it is still verifying whether some of those partial records came from orders older than 90 days.
Exposed addresses create a physical-security risk
The breach is especially sensitive because shipping information can identify not only a cryptocurrency holder but also where they live. That creates potential risks ranging from highly targeted phishing and fraudulent letters to physical targeting.
Physical attacks on crypto holders have become a growing security concern. Chainalysis said home invasions accounted for 37% of violent crypto incidents in 2026, up from 26% in 2023, while approximately $30 million had already been stolen through violent attacks by mid-year.
Annual Crypto Value in Violent Attacks by Outcome (Source: Chainalysis)
There have been no confirmed scams or physical attacks linked to the ShipMonk breach so far. Trezor nevertheless warned affected users to distrust emails, phone calls or physical letters demanding urgent action and to never enter a wallet backup or recovery phrase into a website.
The exposure was limited in part by Trezor’s 90-day retention policy, which requires fulfillment partners to delete or anonymize purchase-related customer data after the period needed for delivery, returns, refunds and replacements.
Trezor plans more private hardware wallet deliveries
The incident is also accelerating attention around how hardware wallets are delivered.
Trezor is preparing an “Anonymous Delivery” option that is designed to reduce the identifying information connected to a hardware wallet purchase. The system will use locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers after delivery.
Trezor plans to launch the option in the European Union by September 2026 and in the United States by the end of the year.
ShipMonk has secured the affected systems and strengthened its security while the investigation continues, according to Trezor. Affected customers have also been contacted directly through Trezor’s official notification email. The company said customers who did not receive the security notice were not affected.
The breach is the first incident since Trezor was founded in 2013 in which a breach involving the company or one of its providers exposed customer phone numbers and shipping addresses.





Be the first to comment