Trezor confirmed a data breach at its shipping partner ShipMonk that exposed personal details of 13,689 customers. The leak includes names, home addresses, phone numbers, and email addresses. No cryptocurrency was moved, and Trezor says its own systems, devices, and wallet backups were untouched.
What got exposed
Of the affected customers, 11,742 had the full set — name, email, phone, and complete shipping address — exposed. The remaining 1,947 had only name, city, and email leaked. The breach hits new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order between May 10 and Aug 8, 2026. Older buyers were spared because Trezor requires partners to delete or anonymize order data 90 days after delivery.
Affected customers received an email from [email protected]. If you didn't get that email, you weren't part of this breach.
The shipping partner
ShipMonk holds SOC 2 Type II certification, an audited security standard, yet still got breached. The incident was disclosed to Trezor on August 10. With names, addresses, and phone numbers in hand, scammers can target crypto buyers with phishing, fake calls, and fraudulent letters.
A familiar pattern
This isn't the first time a hardware wallet maker's customer data has leaked. Ledger had a similar breach in July 2020, exposing roughly 1 million emails and 9,500 full postal details, which led to fake recovery phrase letters. Trezor's breach exposed complete addresses for 11,742 people — more than the 9,500 Ledger buyers hit in 2020. Ledger CEO Pascal Gauthier said at the time there's no correlation between leaked data and funds on wallets.
A Trezor phishing ad appeared days before this disclosure. Fake support call scams have drained millions from holders this year.
What Trezor says
Trezor advises users to treat urgency as a red flag, check official channels, and never enter a wallet backup on a website. The company also promised an Anonymous Delivery option — locker pickup with neutral packaging — targeting the EU by September and the US by the end of 2026. Trezor says this is the first breach since 2013 to expose customer phone numbers and shipping addresses.
The Anonymous Delivery rollout is the next concrete step. EU customers should see it by September, US customers by the end of the year. Until then, Trezor says to treat any urgent request for your recovery phrase as a scam.




