Trezor has alerted 13,689 customers that their personal data was exposed following a breach at ShipMonk, a fulfillment provider handling its hardware wallet shipments.
ShipMonk breach exposes customer data
According to Trezor, ShipMonk notified the company on August 10 after it detected unauthorized access to systems carrying customer order details. Trezor confirmed that the breach did not impact its core infrastructure, hardware wallet devices, or wallet backup information. The exposure was strictly limited to customer data managed by ShipMonk for order fulfillment.
The affected customers are located across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Out of the total, 11,742 individuals had their names, email addresses, phone numbers, and shipping addresses exposed. An additional 1,947 customers had their names, cities, and email addresses compromised, though Trezor continues to review whether some of those records are linked to orders older than 90 days.
The leak has raised security concerns because exposed shipping data can directly identify cryptocurrency owners and provide their location, increasing the risk of targeted phishing, fraudulent communications, or even physical criminal activity.
Physical attacks on crypto owners are an escalating problem. Chainalysis, a blockchain analytics company, reported that home invasions made up 37% of all violent crypto incidents in 2026, up from 26% in 2023. By mid-2026, approximately $30 million in digital assets had been stolen through violent attacks on crypto users.
| Year | Home Invasions (%) | Theft Amount ($ million) |
|---|---|---|
| 2023 | 26 | Data not specified |
| 2026 (mid-year) | 37 | 30 |
No confirmed phishing scams or physical attacks have been traced to the ShipMonk breach so far. However, Trezor advised affected users to be skeptical of urgent requests received via email, phone, or post and strongly cautioned them never to enter wallet backup or recovery phrases on any website.
Trezor highlighted that customers should treat any unsolicited communication with caution and never reveal their wallet recovery information online.
Trezor stated that its 90-day data retention policy helped limit the breach’s impact. This policy requires fulfillment partners to delete or anonymize customer purchase data once the legally required retention period for delivery, returns, refunds, and replacements has passed.
Trezor plans more private hardware wallet deliveries
The incident has increased industry focus on secure delivery practices for hardware wallets.
Trezor is developing an “Anonymous Delivery” service aimed at further reducing the amount of identifying information involved in hardware wallet purchases. This option will use package lockers for pick-up, neutral packaging, generic sender information, and will prompt automatic removal of shipping identifiers once delivery is complete.
Trezor aims to roll out this feature in the European Union by September 2026 and expand it to the United States before the end of the year.
ShipMonk stated that it has secured the affected systems and increased internal security controls while the investigation continues. Trezor has contacted impacted customers through its official notification channels, assuring those who have not received communication were not affected.
This is the first time since Trezor’s founding in 2013 that a data breach involving the company or its providers has resulted in the exposure of customer phone numbers and shipping addresses.
Mini dictionary: ShipMonk – ShipMonk is a US-based company that specializes in e-commerce fulfillment services, managing inventory, packing, and shipping orders for third-party businesses, including hardware wallet manufacturers.





USDT
AAPL
