Trezor Breach at ShipMonk Exposes Data of 13,689 Customers, Wallets Safe
Fulfilment partner ShipMonk leaked names, emails and addresses of 11,742 Trezor buyers; 1,947 more had partial data exposed.

Trezor said Thursday that the personal data of 13,689 customers — nearly 14,000 buyers — was exposed after its fulfilment partner ShipMonk suffered unauthorized access to its systems. The cold-storage wallet maker said its own infrastructure, devices and private keys remain unaffected, but the breach marks the first time customer shipping addresses have leaked in the company’s history.
Of those affected, 11,742 customers had their full name, email address, phone number and shipping address compromised. Another 1,947 had only their name, city and email address exposed. The impacted orders were placed between May 10 and August 8, 2026, by buyers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
What was exposed — and what wasn’t
Trezor was notified of the ShipMonk breach on August 10 and disclosed it publicly three days later. “We have some difficult news to share,” the company wrote on X. “Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.”
The company said it emailed every affected customer directly, and that anyone who did not receive a notification was not part of the breach. Crucially, Trezor stressed that wallet seed phrases and private keys were never stored by ShipMonk and remain untouched. “Nobody from Trezor ever asks for a wallet backup,” the firm warned, flagging the heightened risk of phishing attempts by phone, email or post that typically follow this kind of leak.
Trezor credited its 90-day data retention policy — under which order data is deleted or anonymized 90 days after delivery — with limiting the scope of the exposure. It also said it is rolling out an “anonymous delivery” option this year and is still deciding on the future of its relationship with ShipMonk pending a full incident report.
A pattern across hardware wallet vendors
The incident echoes prior third-party leaks at rival hardware wallet maker Ledger, whose 2020 breach led to years of targeted phishing and extortion campaigns against affected customers, and which reportedly suffered a further incident in 2026. Because shipping-address leaks let scammers pair a real name and physical location with the knowledge that a target owns a hardware wallet, victims often remain targets for phishing long after the original breach is patched.
The disclosure lands amid a broader spike in data breaches globally. Cybersecurity firm SentinelOne reports that breaches are up 17% in 2026 versus 2025, with an average of 2,090 attacks recorded worldwide each week, and month-over-month growth of roughly 3% since January.
Why it matters for wallet holders
No misuse of the leaked data has been confirmed so far, and Trezor’s core promise — that keys never leave the device — remains intact. But for the roughly 11,700 customers whose home address and phone number are now in unknown hands, the practical risk isn’t a hacked wallet; it’s a convincing phishing call, email or letter designed to trick them into revealing a seed phrase themselves. Anyone who purchased a Trezor device between May and August 2026 should treat unsolicited contact referencing that order with suspicion, regardless of how legitimate it appears.
Sources
Related articles
Trezor Breach Grows by 67,000 US Records After ShipMonk Data Wasn’t Deleted
Trezor confirms 67,000 more US customers exposed via ShipMonk; three outlets agree on the figure, but initial breach counts differ.
Ledger Ethereum App Flaw: Patched in v1.22.2 on Aug 13, Company Says
OneKey says it reproduced a transaction-swap bug in Ledger's Ethereum app v1.22.1. Ledger says the fix shipped weeks earlier.
Coldcard Firmware 5.6.1 Forces Manual Entropy After 594.5 BTC Theft
Coinkite's new firmware requires dice rolls or key presses for every seed after a flawed RNG let attackers drain 594.5 BTC from…