Trezor shipping partner data breach hits 13,689 customers
Hardware wallet maker Trezor is warning thousands of customers after a major data breach at logistics partner ShipMonk. Personal data belonging to 13,689 customers in total was viewed by an unauthorised party. The information includes names, email addresses, phone numbers and home addresses. The wallets themselves are safe according to Trezor, but it is precisely the combination of a physical address and the knowledge that someone has bought a hardware wallet that makes the breach sensitive.
Personal data of thousands of customers leaked
ShipMonk informed Trezor on Monday 10 August about unauthorised access to systems where customer data is stored. Trezor uses the company for the storage and shipping of hardware wallets in several countries.
At 11,742 customers, the full name, email address, phone number and shipping address were exposed. A further 1,947 customers were affected by a partial breach, in which name, city of residence and email address were viewed. In total, this concerns 13,689 people.
The breach affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal who received an order between 10 May and 8 August 2026.
According to Trezor, the damage is limited by its policy of deleting or anonymising order data after 90 days. Logistics partners are also required to apply this period. Older orders were therefore no longer present in the affected systems.
Data breach reminiscent of Ledger
The situation recalls the major data breach at hardware wallet maker Ledger in 2020. In that case, personal data of hundreds of thousands of customers was exposed. Later, a database with details of more than 270,000 Ledger customers appeared online, including names, phone numbers and physical addresses.
The consequences of such a leak can last for years. Ledger users still report phishing emails, suspicious phone calls and other attempts in which criminals pose as company employees years after the original breach. It shows why the leaking of customer data from a hardware wallet company is especially sensitive.
A similar risk now arises at Trezor for the affected group. Anyone with the leaked data knows not only where someone lives, but can also deduce that someone at that address has ordered a hardware wallet and therefore possibly owns crypto.
That does not automatically mean it is known how much crypto someone holds. Even so, that information can be valuable to criminals. In addition to digital phishing, this also creates a physical safety risk.
Trezor warns of targeted phishing
Trezor says its own systems, products and hardware wallets have not been compromised. Private keys and wallet backups were therefore not taken via this breach.
The immediate danger is mainly in convincingly disguised scams. With a name, phone number, email address and home address, criminals can more credibly impersonate Trezor, a crypto exchange, bank or other service provider.
Trezor therefore warns users never to enter their wallet backup or seed phrase on a website or share it with anyone. According to the company, this is the first time since its founding in 2013 that a data breach around Trezor has led to the exposure of phone numbers and shipping addresses.
At the same time, Trezor is working on Anonymous Delivery. This option is expected to become available in the EU from September 2026 and in the United States by the end of the year. Users will be able to order under a nickname and collect their package from an automated parcel locker.
The data breach makes clear why such a system can be relevant. A hardware wallet can secure crypto offline, but once order data leaks, a very different problem arises. The coins remain safe on the wallet, while criminals may have access to the owner’s personal data for years.
Not financial advice. CryptoTips We are not a financial advisor and the content on this website is not financial advice. All information on this website is informative and not a recommendation to buy or sell anything. Consult an expert when making financial decisions and only invest money you can afford. You are responsible for your own investments. We use affiliate referrals and may receive commissions for these. Read our full disclaimer.
Affiliate disclosure. Some links on this site are partner/affiliate links. If you sign up with a partner through such a link, we may receive a commission at no extra cost to you. This never influences our reporting. Read our editorial guidelines.