Trezor Discloses ShipMonk Data Breach Affecting 13,689 Customers
Key Takeaways
- •A breach at third-party fulfillment provider ShipMonk exposed personal data belonging to 13,689 Trezor customers across seven countries, including full names, shipping addresses, phone numbers, and email addresses.
- •Trezor's own internal systems, hardware wallets, private keys, and wallet backups were not compromised in the incident.
- •A 90-day data retention policy requiring deletion or anonymization of purchase records significantly limited the scope of exposed data to orders delivered since approximately May 10.
- •Affected customers are now considered high-value targets for social engineering attacks, as shipping records implicitly confirm ownership of cryptocurrency hardware wallets.
- •Trezor plans to launch an Anonymous Delivery option using locker collection points and neutral packaging in the EU by September, with a U.S. rollout expected before the end of 2026.

Personal data belonging to 13,689 Trezor customers was exposed following a security breach at ShipMonk, the third-party fulfillment provider that handles shipping for Trezor Shop orders across multiple markets.
Trezor disclosed the incident on August 13, noting that the breach affects customers who received orders in the U.S., U.K., Sweden, Colombia, Brazil, Italy, or Portugal during the 90 days preceding August 8. ShipMonk informed Trezor of unauthorized access to systems containing customer data on August 10.
Scope of Exposed Data
Full names, shipping addresses, phone numbers, and email addresses were exposed for 11,742 customers. An additional 1,947 customers had their names, cities, and email addresses accessed.
Trezor emphasized that its own systems, hardware wallets, private keys, and wallet backups were not compromised. However, the exposed shipping records implicitly confirm that these individuals own cryptocurrency hardware wallets, making them high-value targets for social engineering. With names, addresses, and phone numbers in hand, scammers can craft targeted phishing emails, phone calls, and physical mail impersonating Trezor, cryptocurrency exchanges, banks, or delivery companies.
A comparable attack previously resulted in a Ledger user losing approximately $1.07 million after receiving a counterfeit support letter that directed them to a phishing site requesting their recovery phrase.
Trezor contacted all affected customers directly from help@trezor.io. Customers who did not receive a notification email are not part of the identified breach population.
Data Retention Policy Limited Exposure
Trezor requires purchase information to be deleted or anonymized 90 days after delivery, and ShipMonk operates under the same retention requirement. As a result, older customer records had already been purged from the affected systems. Without this policy, the breach could have exposed shipping data accumulated over a much longer period rather than only orders delivered since May 10.
The incident illustrates a broader challenge for companies that maintain strong internal security but rely on third-party vendors for logistics, printing, or customer support—each external partner represents an additional attack surface outside the primary company's direct control.
Trezor plans to introduce an Anonymous Delivery option in the European Union by September, with a U.S. rollout expected before the end of 2026. The proposed system would utilize locker collection points, neutral packaging, generic sender details, and automatic deletion of shipping identifiers following delivery.
Trezor Urges Vigilance Against Phishing
Trezor is advising affected customers to treat any unsolicited communications requesting immediate action or personal information as suspicious. The company reiterated that a wallet backup should never be entered into any website or shared with anyone claiming to represent Trezor.
The incident occurs amid a broader wave of cryptocurrency wallet security events. Coldcard-linked wallet drains constituted the largest crypto security loss in July, while a separate Ethereum whale recently lost $25.6 million through a phishing attack, having previously lost $24.2 million from the same wallet in 2023.
ShipMonk has secured the affected systems as its investigation continues, and Trezor's operations remain online. This marks the first breach since Trezor's founding in 2013 to expose customer phone numbers and shipping addresses.