Trezor reports data breach through ShipMonk, exposing 13,689 customer records globally

This breach is described by sources as Trezor's first data exposure since 2013, highlighting its rarity in the company’s history.
Trezor emphasized that its own systems were not compromised and the devices remain secure, while warning users to avoid sharing wallet backups to guard against phishing.
A contractual 90-day data-retention clause with fulfillment partners limits how long order data is kept, causing older records to be deleted or anonymized after delivery.
Industry context shows phishing and impersonation risks in crypto, with comparable exposure events (e.g., Ledger) illustrating the potential consequences of exposed contact and shipping data.
Trezor has disclosed a data breach at its third-party shipping partner, ShipMonk, exposing personal data of 13,689 customers across seven countries, including the US, UK, Sweden, and Brazil. The Block reported that the breach affected orders placed between May 10 and August 8, 2026.
Of those affected, 11,742 customers had full exposure — names, emails, phone numbers, and home addresses — while 1,947 had partial exposure, with only names, city, and email revealed, according to Finbold. Trezor stressed that its own systems and devices were not touched.
Trezor was quick to draw a clear line. The breach came from ShipMonk's systems, not Trezor's own infrastructure. Mpost noted that Trezor confirmed its hardware wallets remain fully secure and that no seed phrases, passwords, or wallet data were exposed in the incident.
Order numbers were also part of the exposed data. Trezor said it is now investigating the incident and has tightened security protocols with ShipMonk. CoinGape described this as Trezor's first data exposure since 2013, making it a rare event in the company's history.
One detail worked in customers' favor. Trezor has a contractual 90-day data-retention policy with its fulfillment partners. Under this rule, order data is deleted or anonymized after delivery. That means older orders were already wiped before the breach occurred.
Finbold reported that this policy significantly limited the amount of data at risk. Only orders placed within that 90-day window — between May 10 and August 8, 2026 — were exposed. The policy acted as a built-in damage cap on the breach.
Trezor warned that exposed customers could now face targeted phishing and impersonation attempts. Phishing means scammers pose as a trusted company — like Trezor — to trick people into giving up sensitive information. The Block noted Trezor urged customers to rely only on official Trezor channels for any communication.
Trezor specifically warned users never to share their wallet backup phrases, no matter who asks. This risk is not new to crypto. A major breach at hardware wallet rival Ledger in 2020 exposed 270,000 customers' data and led to a wave of phishing attacks, showing how dangerous leaked shipping data can be in the crypto world.
Trezor responded with more than just warnings. The company announced it is developing an Anonymous Delivery option, which would let customers receive orders without linking their real identity or address to the purchase. Head Topics reported the move as a direct response to the ShipMonk breach.
The announcement signals a broader shift in how crypto hardware companies may handle logistics going forward. Keeping customer shipping data away from third parties could become a key selling point. For now, Trezor told affected customers to stay alert and watch for suspicious messages.
Publishers
17
Articles
28
Reach
45