NewsCryptoTrezor Says ShipMonk Breach Exposed Data of About 13,700 Customers

Trezor Says ShipMonk Breach Exposed Data of About 13,700 Customers

Author: Blockonomi·

Key Takeaways

  • Trezor said ShipMonk’s unauthorized access exposed personal order data tied to roughly 13,700 recent customers.
  • A total of 11,742 customers had full details exposed, while 1,947 customers had partial exposure.
  • The breach affected customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
  • Trezor said its internal systems, products, and private keys were not compromised.
  • The company warned that the leaked data could be used in targeted phishing attempts and is preparing an Anonymous Delivery option for future orders.
Trezor Says ShipMonk Breach Exposed Data of About 13,700 Customers

A data breach at Trezor’s shipping partner ShipMonk exposed information linked to roughly 13,700 recent customers, according to the hardware wallet maker.

Trezor said the outside party accessed names, emails, phone numbers, and addresses tied to orders placed between May and August 2026. The company said its internal systems and private keys were not compromised, but the exposed order data could still be used in phishing attempts that rely on convincing customers with personal details.

The incident affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor said ShipMonk informed it on August 10, 2026, that unauthorized access had occurred in its order systems. The affected window covers orders placed between May 10 and August 8, 2026.

According to Trezor, 11,742 customers had full details exposed, including name, email, phone number, and address. Another 1,947 customers had partial exposure limited to name, city, and email.

Trezor said its 90-day retention policy helped limit the scope of the breach because older order records had already been deleted from ShipMonk systems by the time the incident was discovered. The company described the event as the first breach since its 2013 founding to expose phone numbers and shipping addresses.

“We absolutely understand how serious this is,” Trezor said, acknowledging the risk to affected customers. The company said support channels remain open for anyone seeking help.

Binance co-founder Changpeng Zhao commented on the incident, saying hardware wallets are generally viewed as more secure than software options. He said the breach highlights an advantage of software self-custody tools, which do not require shipping a device tied to a customer’s identity. Zhao added, “Not saying hardware wallets are ‘bad’. Just different risk profiles.”

Not a great month for hardware wallets. Trezor disclosed a breach at its shipping provider affecting ~13.7K recent customers. ~11.7K had full name, email, phone and shipping address exposed. Trezor systems/private keys were not compromised. The leak directly links identities and…

— CZ BNB (@cz_binance) August 13, 2026

Trezor urged affected customers to be cautious of unexpected emails, calls, or letters. The company recommended verifying any communication against its official blog and social channels before responding. It also reminded users never to enter a wallet recovery phrase online or share it with anyone.

For future orders, Trezor outlined steps that can reduce data exposure, including using an email address not linked to a real identity, paying with crypto or disposable cards, and using a P.O. Box, though identification may still be required for pickup.

The company also announced an upcoming Anonymous Delivery option designed to reduce identity exposure during shipping. The feature will use a dedicated checkout, locker pickup, and neutral packaging with no visible sender name. Trezor said it plans to launch the option in the European Union by September 2026 and in the United States by year-end.

Trezor reiterated that no company systems, products, or services were affected by the ShipMonk breach. It said devices already in customers’ hands remain secure and that private keys were never exposed. The company said the main risk now is an increase in targeted phishing attempts.