Trezor data breach at shipping partner ShipMonk exposes data of 13,689 customers
Key Takeaways
- •A breach at fulfillment provider ShipMonk exposed personal data belonging to 13,689 Trezor customers across seven countries, covering orders placed between 10 May and 8 August 2026.
- •For 11,742 customers the exposed data comprised full name, delivery address, phone number and email, creating phishing and physical targeting risks for likely crypto holders.
- •Trezor stated that devices, private keys, wallet backups and its own systems were not accessed, and attributed the limited scope to a contractual 90-day data retention policy for fulfillment partners.
- •Trezor announced an 'Anonymous Delivery' option based on nicknames and automated parcel lockers, expected in the EU from September 2026 and in the US towards the end of 2026.
- •Because SatoshiLabs is based in the Czech Republic, GDPR requires notification to the supervisory authority ÚOOÚ within 72 hours, though whether and when Trezor filed such a report is not publicly documented.

An unauthorised third party has accessed customer data held by Trezor's fulfillment partner. The breach affects 13,689 customers across seven countries. For 11,742 of them, the exposure covers full name, delivery address, phone number and email address.
Trezor is a hardware wallet brand owned by the Czech company SatoshiLabs, which brought the first widely available crypto hardware wallet to market in 2013. Its devices store private keys offline, separated from the internet, which places them among the safest forms of self-custody. That same security focus makes the customer list valuable, because anyone on it very likely holds crypto. The incident covers orders from the period between 10 May and 8 August 2026, with shipments going to the US, the UK, Sweden, Colombia, Brazil, Italy and Portugal. The service provider involved is ShipMonk, a fulfillment company headquartered in Fort Lauderdale, Florida, that operates warehouses across North America and Europe for online merchants. According to the company, devices, private keys and wallet backups remained untouched. In response, the manufacturer also announced an anonymous shipping option.
What the Trezor data breach at ShipMonk exposed
ShipMonk informed Trezor on 11 August 2026 about the unauthorised access to systems holding customer data. Because Trezor sells its devices online, external partners handle delivery. Fulfillment providers take care of storage, picking and shipping, and therefore need full delivery addresses and contact details of end customers — without those details, no parcel gets delivered. Exactly this data set lay exposed. Two days later, the company went public with the case.
The affected customers fall into two groups. For 11,742 customers the exposure is complete, including name, delivery address, phone number and email address. For another 1,947, it is limited to name, city and email address. Together, the two groups make up the reported 13,689 cases. Names and phone numbers enable targeted phishing calls, while the delivery address makes the holder physically locatable.
According to the company, the access covered neither devices nor private keys or wallet backups, and Trezor's own systems likewise stayed out of the attacker's reach. Overall, the incident hits the logistics layer around the product. The manufacturer attributes the limited scope to a strict 90-day data retention policy, which applies contractually to fulfillment partners as well. Older order data no longer exists there, so earlier shipments fall outside the affected period. Trezor also notified every affected customer separately by email and apologised publicly for the incident. The investigation continues, and updates are to appear on the company blog.
Why an address list puts crypto holders at particular risk
A buyer list for hardware wallets is not an ordinary customer base. Anyone who links a home address to a Trezor purchase identifies a probable target, since that buyer very likely holds larger crypto holdings.
The precedent dates from 2020. At Paris-based competitor Ledger, attackers took around 1.1 million email addresses through a third-party interface. They also obtained roughly 272,000 detailed records with full name, phone number and postal address. In December 2020, that data eventually ended up publicly online. Soon after, broad phishing and extortion campaigns hit Ledger customers, in some cases with threats to their physical safety. Ledger later addressed the incident in a public statement.
The threat landscape has worsened since then. Chainalysis, a New York-based blockchain analytics firm, counted 46 violent crypto-related incidents worldwide in the first half of 2026, up from 40 a year earlier. These so-called wrench attacks include kidnappings, home invasions and hostage takings. Perpetrators seized around USD 30 million in the first half of the year alone, and in total attempted to obtain USD 107 million. According to Chainalysis, that puts 2026 on track to break the 2025 full-year record of USD 58 million. The attackers' success rate, however, fell from 49% in 2025 to 26%: the number of attempts is rising while fewer of them succeed.
Regionally, France stands out. Chainalysis counts 30 publicly known incidents there, while authorities have recorded more than 70. The analytics firm identifies a data breach at the tax administration as one cause. The leak dates to 2024 and affected the greater Paris area. An official allegedly stole and sold records of wealthy crypto owners, including names, addresses, phone numbers and holdings. Criminal groups then used that material to plan their attacks, picking their targets based on the recorded holdings. Ultimately, the path from an address list to the front door is documented.
Anonymous delivery as an answer to the address problem
About an hour after the first notice, Trezor announced an option called "Anonymous Delivery". It targets exactly the data category that lay exposed at ShipMonk. Customers first enter a nickname or a label ID at checkout instead of their real identity. The shipment then goes to an automated parcel station, where buyers collect it themselves. Automated parcel lockers of this kind are already an established delivery format across much of Europe. Real name and home address no longer sit together at the service provider, and a courier with name and address at the front door disappears.
In addition, the packaging stays unmarked and carries a generic sender, and the provider sends the pickup PIN by email or SMS only. Pickup stations replace the home address as the delivery point, and the buyer's real name no longer appears on the shipment. A compromised service provider would consequently give up only pseudonyms and pickup points. Trezor calls the project its current top priority.
The option should become available in the EU from September 2026. In the US, it is due towards the end of 2026. Until then, orders continue to run through the existing channels. Meanwhile, the timeline shows the limits of the announcement: for the 13,689 customers already affected, the new shipping option changes nothing. Ultimately, the announcement is an admission that shipping data is a security problem in its own right.
Reporting duties and the pattern behind the incident
Behind Trezor stands SatoshiLabs, based in the Czech Republic, so European data protection law applies to the incident. The General Data Protection Regulation requires a report to the supervisory authority within 72 hours, in particular when a breach poses a risk to those affected. For infringements of the regulation, the framework provides for fines of up to EUR 20 million or 4 percent of a company's worldwide annual turnover. Jurisdiction in this case would fall to the Czech supervisory authority ÚOOÚ. Since the deadline starts with knowledge of the breach, the clock began on 11 August 2026. Still, whether and when Trezor filed such a report is not publicly documented. Beyond the EU, the seven affected countries bring further notification regimes into play; in the US, all fifty states operate their own breach-notification statutes.
Trezor itself has met the mechanism before. In April 2022, attackers compromised its newsletter account at the email provider Mailchimp and used it to send customers phishing emails about a purported data breach; Trezor confirmed at the time that no such breach had taken place. The recurrence of the pattern stands out. In all these cases, the data sat outside the systems that crypto users controlled themselves: previously a marketing interface, a newsletter account and a tax authority, now a shipping provider. As a result, third-party providers form a recurring attack vector against crypto holders. The cryptography of the devices was never the problem. For buyers, custody security starts at the order, and the logistics behind it remain vulnerable.