Hardware wallet manufacturer Trezor has confirmed that personal information belonging to approximately 13,689 customers was exposed following a data breach at ShipMonk, a third-party fulfillment provider used to ship Trezor devices.
The incident exposed names, email addresses and other contact information, with 11,742 customers having their full shipping addresses and phone numbers compromised. Trezor said its own infrastructure, hardware wallets and services were not affected.
ShipMonk notified Trezor on August 10, 2026 that an unauthorized party had accessed systems containing customer fulfillment data. Trezor publicly disclosed the incident on August 13 and said the investigation remains ongoing.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
Nearly 14,000 customers affected
According to Trezor, the incident primarily affects customers whose orders were fulfilled by ShipMonk between May 10 and August 8, 2026. However, the company later said it is working with ShipMonk to verify whether a smaller group of older customer records was also included.
The affected customers fall into two groups:
- 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed.
- 1,947 customers had their names, cities and email addresses exposed.
ShipMonk also stores order numbers required to fulfill customer purchases.
Trezor initially said the breach involved orders shipped to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
All affected customers have been notified directly by email, according to the company. Trezor also said customers who purchased devices through Amazon were not affected because those orders are fulfilled by a separate logistics provider.
Trezor wallets remain secure
Trezor emphasized that the breach was limited to ShipMonk’s systems and did not compromise Trezor’s own infrastructure, hardware wallets or firmware. No wallet backups, recovery seeds or cryptocurrency assets were exposed.
While the stolen information cannot directly access customer wallets, it could enable convincing phishing and social engineering campaigns targeting cryptocurrency users. Attackers may impersonate Trezor, cryptocurrency exchanges, banks or delivery providers using the exposed personal information.
Trezor reminded customers that it will never ask for a wallet backup or recovery seed and warned users to remain cautious of unsolicited emails, phone calls and physical mail claiming to be from the company.
Cryptocurrency users have increasingly become targets of phishing campaigns that leverage leaked customer information. Earlier this year, BreachNews reported that a fake Ledger Live application allegedly stole $9.5 million from more than 50 victims after users were tricked into revealing sensitive wallet information.
Questions remain over data retention
Trezor said ShipMonk is contractually required to delete or anonymize shipping information 90 days after delivery, allowing enough time to process returns, refunds and warranty replacements.
Because the second group of affected customers may include older orders, Trezor said it is working with ShipMonk to determine why those records remained accessible and to verify the exact scope of the exposure.
ShipMonk requires customer names, shipping addresses, phone numbers and email addresses to fulfill hardware wallet orders on Trezor’s behalf.
According to Trezor, ShipMonk has secured the affected systems and implemented additional security measures following the incident. ShipMonk had not issued a separate public statement at time of publication.
Exposure increases phishing risks
The exposure of home addresses alongside names, email addresses and phone numbers presents an elevated risk for hardware wallet owners because it identifies individuals who have purchased cryptocurrency security devices.
Although the breach does not expose wallet credentials or digital assets, the information could make phishing, impersonation and social engineering attacks significantly more convincing.
Trezor said this is the first incident in the company’s history to expose customer phone numbers and shipping addresses. Previous third-party security incidents involved other categories of customer information but did not include shipping addresses.
The company said it continues to work with ShipMonk to determine the full scope of the incident and urged affected customers to treat any unsolicited communications relating to their wallets or orders with caution.












