TLDR:
- The ShipMonk breach exposed names, emails, phone numbers and addresses of Trezor buyers online.
- Trezor says 11,742 customers had full data exposed, while 1,947 saw partial exposure occur.
- Trezor confirmed its internal systems and private keys were not compromised during the breach.
- CZ says the breach highlights an advantage software self-custody crypto wallets hold over hardware ones.
A Trezor data breach at shipping partner ShipMonk has exposed information linked to roughly 13,700 recent customers.
The hardware wallet maker confirmed that names, emails, phone numbers, and addresses were accessed by an outside party.
The exposure covers orders placed between May and August 2026. Trezor stated its internal systems and private keys were not touched. The company has begun notifying users and published guidance on avoiding phishing attempts.
Breach Details and Scope
ShipMonk informed Trezor on August 10, 2026, that unauthorized access had occurred within its order systems. The affected window covers orders placed between May 10 and August 8, 2026.
Customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were included. Trezor said the breach was limited to fulfillment data rather than wallet security systems.
The company reported that 11,742 customers had full details exposed, including name, email, phone number, and address. A further 1,947 customers had partial exposure limited to name, city, and email.
Trezor credited its 90-day retention policy with limiting the scope. Older order records had already been deleted from ShipMonk systems by the time of the breach.
Trezor called the event the first breach since its 2013 founding to expose phone numbers and shipping addresses. Trezor said, “We absolutely understand how serious this is,” acknowledging the risk to affected customers. Support channels remain open for customers seeking further assistance.
Binance co-founder Changpeng Zhao commented on the incident, noting hardware wallets are generally seen as more secure than software options.
He said the breach shows an advantage of software self-custody tools, which skip shipping a device tied to identity. Zhao added, “Not saying hardware wallets are ‘bad’. Just different risk profiles.”
Trezor Response and Safety Guidance
Trezor urged affected customers to treat unexpected emails, calls, or letters with caution. The company recommended checking any communication against its official blog and social channels before responding. Customers were reminded never to enter a wallet recovery phrase online or share it with anyone.
The company outlined steps buyers can take to limit data exposure on future orders. Suggestions included using an email address not linked to a real identity and paying with crypto or disposable cards. A P.O. Box can also reduce address exposure, though identification may still be required for pickup.
Trezor announced an upcoming Anonymous Delivery option built to reduce identity exposure during shipping. The feature will use a dedicated checkout, locker pickup, and neutral packaging with no visible sender name.
Trezor plans to launch the option in the European Union by September 2026 and in the United States by year-end.
Trezor reiterated that no company systems, products, or services were affected by the ShipMonk breach. Devices already in the customer’s hands remain secure, and private keys were never exposed. The company said the main risk going forward is an increase in targeted phishing attempts.
The post Trezor Data Breach: ShipMonk Hack Exposes 13,700 Customer Records appeared first on Blockonomi.
Source: https://blockonomi.com/trezor-data-breach-shipmonk-hack-exposes-13700-customer-records/





Be the first to comment