Press play to start listening
Trezor has notified 13,689 customers that personal information linked to recent hardware-wallet orders was exposed in a data breach at shipping provider ShipMonk. The company disclosed the incident on August 13 and warned recipients to expect more targeted phishing attempts.
For context, Trezor is a Czech company that makes hardware wallets for Bitcoin and other cryptocurrencies. Its devices keep the private keys used to access digital assets separate from internet-connected computers, reducing exposure to online theft. In this incident, customer order and delivery information was exposed, not cryptocurrency or data stored on Trezor devices.
According to Trezor’s account of the incident, the exposed records belonged to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal who received an order during the 90 days before August 8, 2026.
Most of the affected customers, numbering 11,742, had their full names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 records contained a customer’s name, city and email address. Trezor said everyone included in the incident had been contacted separately by email.
However, older orders were not included because Trezor requires customer data to be deleted or anonymised 90 days after delivery. The company said it had negotiated the same retention terms with fulfilment partners, limiting the information held in ShipMonk’s systems when the breach occurred.
Trezor said its own systems and hardware wallets remain secure. Its disclosure lists order and contact information only, with wallet backups and private keys not included among the exposed data.
Even without wallet credentials, the exposed information gives criminals useful material for convincing scams. An email containing a customer’s real name, phone number and delivery address can appear more credible when it claims to concern a Trezor order, device update or account problem.
Anyone receiving such a message should avoid links and contact details supplied by the sender. Trezor said customers should never type their wallet backup into a website or disclose it to another person, and should check company announcements only through official channels. Genuine Trezor staff will not ask for a recovery seed.
Following the breach, Trezor said it is prioritising an Anonymous Delivery option intended to separate hardware-wallet purchases from customers’ home addresses and legal names. The company aims to introduce the service in the European Union by September and in the United States by the end of 2026.
Under the planned service, buyers would use a dedicated checkout, enter a nickname or label identifier, and collect the package from an automated parcel locker. Orders would arrive in unbranded packaging with a generic sender label, while the carrier would use email or SMS only to send the collection PIN.
Trezor said it is continuing to investigate the ShipMonk incident and will publish updates on its blog. The company has not reported any compromise of customer funds, devices, or wallet credentials connected to the breach.
This is not Trezor’s first third-party data exposure. In January 2024, unauthorized access to a support portal used by the company may have exposed the email addresses and names or nicknames of up to 66,000 people. Trezor notified all 66,000 contacts, although it did not confirm that every record had been accessed or stolen.
(Photo by rc.xyz NFT gallery on Unsplash)
