Trezor Data Breach Through ShipMonk Exposes Personal Data of 13,689 Users; Crypto Wallets Unaffected
Key Takeaways
- •Approximately 11,742 Trezor customers had personal information including names, email addresses, phone numbers, and shipping addresses exposed through a breach at logistics provider ShipMonk.
- •No cryptocurrency wallets, private keys, recovery seeds, or Trezor internal systems were compromised in the incident.
- •The breach creates elevated phishing risks because hardware wallet purchasers have effectively self-identified as cryptocurrency holders, making them high-value targets for social engineering attacks.
- •Affected customers are located across at least seven countries, including the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
- •Trezor is developing an Anonymous Delivery feature with options such as locker pickup, neutral packaging, and automatic deletion of shipping identifiers to reduce future customer data exposure.

Trezor has notified customers of a data breach involving ShipMonk, a third-party logistics provider that handles fulfillment for certain Trezor orders. While no cryptocurrency wallets, private keys, or Trezor internal systems were compromised, the exposed personal information could enable more convincing phishing campaigns against affected users.
ShipMonk Breach Details
On August 10, ShipMonk informed Trezor that an unauthorized third party had accessed systems containing customer order data. Trezor stated that the investigation is ongoing.
According to Trezor's estimates, 11,742 customers had their names, email addresses, phone numbers, and shipping addresses exposed. An additional 1,947 customers may have had their names, city-level location information, and email addresses accessed.
The affected orders initially cover customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders during the relevant period.
Trezor maintains a 90-day data retention policy, meaning ShipMonk should only have had access to historical data for a 90-day window. However, the company has cautioned that some of the 1,947 partially exposed records may include older orders, a detail still being confirmed with the logistics provider.
Customers who received an official email notification from help@trezor.io should assume their information was exposed. Trezor stated that individuals who did not receive such an email are unaffected.
Wallet Security Intact
The breach did not impact Trezor's internal systems, hardware devices, or wallet backups. No private keys or recovery seeds were accessed.
Primary Risk: Targeted Phishing
The stolen personal data could allow criminals to craft highly convincing scams. A victim's real name, phone number, or delivery address could be leveraged to impersonate Trezor, a cryptocurrency exchange, a bank, or another trusted entity. Attackers may use emails, phone calls, or even physical mail to pressure users into disclosing sensitive information.
The risk is amplified by the nature of the exposed list: customers who purchased a hardware wallet have effectively self-identified as cryptocurrency holders, making them disproportionately attractive targets for social engineering campaigns. This pattern has been observed before in the hardware wallet industry — a 2020 breach at Ledger exposed over 270,000 customers' personal data and was followed by sustained phishing attacks and extortion attempts that continued for years afterward.
Trezor advises potentially impacted customers to be especially cautious of messages that create urgency or request personal details. Above all, users should never enter their wallet backup or recovery seed into any website. Trezor emphasized that legitimate customer support will never ask users to reveal their wallet backup.
Privacy Measures for Future Orders
In response to the incident, Trezor is highlighting steps customers can take to reduce the exposure of personal information when purchasing hardware wallets. The company recommends using an email address not linked to a real name, paying with cryptocurrency where possible, and using a P.O. Box for delivery.
Additionally, Trezor is developing an Anonymous Delivery feature designed to minimize exposure of shipping details. The planned feature includes options such as locker pickup, neutral packaging, generic sender information, and automatic deletion of shipping identifiers upon delivery. If implemented, such measures could set a new operational privacy standard among hardware wallet vendors, many of whom still rely on conventional e-commerce fulfillment chains that retain identifiable customer records.
Source: Trezor official statement