Trezor shipping partner breach exposes data of 13,689 customers
A ShipMonk breach exposed Trezor order data for 13,689 customers, raising phishing risks without compromising wallet keys.
By Dev Ramirez · Crypto Correspondent
· 3 min read
The Trezor shipping partner breach exposed order-related personal information for 13,689 customers, according to reports published August 13. For hardware-wallet owners, the immediate concern is targeted impersonation, while Trezor said its own systems, customers’ devices, private keys and wallet backups were not compromised.
ShipMonk, the logistics company that stores and ships Trezor products, told Trezor on August 10 that an unauthorized party had accessed systems holding customer data, according to SQ Magazine. Trezor subsequently disclosed the incident and said it had contacted affected customers.
Which Trezor customers were affected by the shipping breach?
The incident covered orders delivered between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, according to Decrypt’s reporting published by Yahoo.
- 11,742 customers had full names, phone numbers, email addresses and street addresses exposed.
- 1,947 customers had names, cities and email addresses exposed.
- 13,689 customers were affected in total.
A delivery record can show that someone bought a hardware wallet, but it does not establish that the person still owns cryptocurrency or reveal the balance of any wallet. Trezor said no device information, private key or wallet backup was involved.
Why the exposed data still creates a security risk
Names, phone numbers, email addresses and delivery addresses can make fraudulent messages appear more convincing. Trezor advised customers to treat unexpected contact with suspicion and not enter a wallet backup online, according to Yahoo’s report.
A wallet backup, often called a recovery seed, is the set of words that can restore access to a crypto wallet. Anyone seeking that information is seeking control over the assets, which is why holders should keep it private and avoid providing it in response to an email, phone call or message.
The reports do not establish how the unauthorized access occurred, how long it lasted, whether the information was published, or whether it has been misused. They also do not report financial losses from this incident.
Why older Trezor orders were said to be outside the breach
Trezor said it requires logistics partners to delete or anonymize order data 90 days after delivery. The company attributed the limited time window to that policy, meaning older order records were no longer held by the shipping provider, according to SQ Magazine. That is a company-reported explanation, not an independent audit of ShipMonk’s records.
Trezor also said it was accelerating an Anonymous Delivery option with locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers. The company’s stated target is the European Union by September and the United States by the end of the year.
This is separate from Trezor’s January 2024 incident involving a third-party support-ticketing portal. In that case, Trezor said contact information for up to 66,000 support contacts may have been accessed, with names or nicknames and email addresses potentially exposed. Trezor’s 2024 security update said no digital assets were compromised in that earlier event.
This story draws on original reporting from Decrypt.