cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Trezor Shipping Breach Exposes Data of 13,689 Customers

Trezor Shipping Breach Exposes Data of 13,689 Customers

Van Thanh Le

Van Thanh Le

PublishedAug 13 2026

UpdatedAug 13 2026

8 hours ago4 minutes read
Trezor Shipping Breach Exposes Data of 13,689 Customers

Customer addresses and phone numbers were compromised, but wallets and private keys remained secure

TL;DR

  • Trezor said a breach at shipping provider ShipMonk exposed personal data belonging to 13,689 customers.
  • Trezor’s systems, hardware wallets, private keys and wallet backups were not compromised, and no crypto moved.
  • Customers whose home addresses and phone numbers leaked face increased phishing, impersonation and potential physical-security risks.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Trezor said a breach at shipping provider ShipMonk exposed personal information belonging to 13,689 customers, including thousands of full shipping addresses and phone numbers. The incident affected customer-order records rather than Trezor’s internal systems: the hardware-wallet maker said its devices, private keys and wallet backups were not touched, and no cryptocurrency moved as a direct result of the breach.

ShipMonk stores and ships Trezor orders. The logistics provider notified Trezor on Aug. 10, 2026, that an unauthorized intruder had accessed systems containing customer records, and Trezor publicly disclosed the incident on Aug. 13.

The compromised records fall into two groups:

Affected customers Exposed information
11,742 Name, email address, phone number and full shipping address
1,947 Name, city and email address

The affected orders were delivered between May 10 and Aug. 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor requires shipping partners to delete or anonymize order information 90 days after delivery, so earlier shipments had already been removed from the relevant systems.

Trezor notified affected customers by email from [email protected]. The company said customers who did not receive that notification were not part of the exposed dataset.

“We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…” Trezor said in its disclosure.

Wallet security was not breached

Trezor said the incident did not compromise the systems responsible for protecting customer cryptocurrency. Its internal infrastructure, hardware devices, private keys and wallet backups remained secure, separating the ShipMonk breach from an incident in which attackers directly obtain credentials capable of authorizing transactions.

“This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses,” Trezor said.

ShipMonk holds SOC 2 Type II certification, an audited security standard. The compromise nevertheless occurred in systems holding logistics and customer-order information.

The stolen records did not include wallet balances, blockchain addresses, seed phrases or private keys. The exposed data can identify someone as a Trezor customer, however, and customers whose full contact details were taken can now receive communications containing accurate personal information.

Trezor warned that scammers may use the data to send fraudulent emails, make phone calls, mail physical letters or impersonate Trezor, banks and cryptocurrency exchanges. Accurate names, addresses and telephone numbers can make those approaches appear more credible to their targets.

The company advised users to treat urgent requests as a warning sign and independently verify suspicious communications through official Trezor channels. “Never enter your wallet backup on a website or share it with anyone,” Trezor wrote.


We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!

Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.


Address exposure raises physical-security concerns

Full residential information creates risks beyond online phishing because it identifies a hardware-wallet customer at a specific physical location. Criminals have used personal information connected with cryptocurrency ownership to select targets for kidnappings, home invasions and other attacks intended to force victims to transfer assets.

A French couple was reported on Aug. 12 to have been targeted in three home invasions in less than one month after moving into a property formerly owned by crypto millionaires whose tax information and address had leaked onto the dark web.

Chainalysis data showed more than $30 million had been stolen through violent crypto-related attacks during the first half of 2026. That pace was on track to exceed the $58 million recorded for the full year of 2025.

The risk from leaked customer information can also persist long after the original breach. Ledger experienced a major customer-data exposure in July 2020, providing a historical comparison for how leaked contact information can later be used in targeted scams.

Historical measure Figure
Ledger customer email addresses exposed Roughly 1 million
Ledger customers with full postal details exposed About 9,500
Ledger customer records containing broader personal information later published More than 270,000

Names, email addresses, phone numbers and, for some Ledger customers, home addresses were later published on a hacking forum, followed by phishing attempts and reports of harassment. Physical letters designed to obtain recovery phrases also reached customers’ homes years after the original exposure.

Customers were still reporting fraudulent calls and physical letters six years later from people impersonating Ledger and attempting to obtain seed phrases or other sensitive information.

Ledger CEO Pascal Gauthier addressed concerns about what leaked customer information could reveal about cryptocurrency holdings, saying, “there is no way to make any correlation between the data that has leaked and the funds on your wallet.”

A separate third-party incident affected Ledger customers in January 2026 after unauthorized access to order data held by e-commerce provider Global-e exposed names and contact information.

Trezor was also already being used as a lure in phishing campaigns before the ShipMonk disclosure. A Trezor-themed phishing advertisement appeared days before the breach became public, while separate fake customer-support call schemes had drained millions of dollars from cryptocurrency holders during the year.

Trezor plans Anonymous Delivery option

The incident highlights the exposure created by the commercial process surrounding hardware wallets. A device can protect cryptographic credentials while logistics and e-commerce providers still hold conventional customer records needed to process and deliver orders.

Trezor plans an Anonymous Delivery option based on locker pickup and neutral packaging to reduce the personal information associated with receiving a hardware-wallet order. The company is targeting a European Union rollout by September 2026 and a U.S. launch by the end of 2026.

Privacy-conscious customers were also advised to consider ordering through an email address that is not connected to their real name and paying with cryptocurrency where possible. Those practices can reduce some identifying links around a purchase, while Trezor’s planned delivery system addresses the shipping stage.

Affected Trezor customers should treat possession of correct personal information as insufficient proof that a caller, email sender or letter genuinely comes from Trezor. The breach gives potential scammers access to customer details, but it does not provide the wallet backup or private keys needed to authorize cryptocurrency transactions.

FAQ

Did the Trezor breach compromise customers’ crypto?

No. Trezor said its devices, private keys and wallet backups remained secure.

How can affected customers identify their status?

Trezor sent notifications from [email protected] to customers included in the exposed dataset.

What scams did Trezor warn about?

Fake emails, calls, letters and impersonation of Trezor, banks or cryptocurrency exchanges.

What is Trezor changing after the incident?

It plans locker-based Anonymous Delivery with neutral packaging in Europe and the United States.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.13.12
© 2017 - 2026 COIN360.com. All Rights Reserved.