Trezor disclosed a data breach at its fulfillment provider ShipMonk on Aug. 13, exposing personal information of about 13,689 hardware wallet buyers. The breach includes delivery addresses for 11,742 people, linking identifiable individuals to crypto hardware purchases and raising the risk of targeted physical attacks. Trezor's own systems were not breached, and wallets remain secure, but the exposed data is enough to put buyers at risk.
What was exposed
The exposed records include names, email addresses, phone numbers, and shipping addresses for the larger group. A separate set of 1,947 people had names, cities, and emails exposed. The fully exposed records cover orders from May 10 to Aug. 8, though additional records may be older. The exposure links identifiable people to hardware wallet purchases, creating physical security risks.
How the breach happened
ShipMonk notified Trezor on Aug. 10 of unauthorized access. Trezor's own systems were not breached, and wallets remain secure. The company says fulfillment partners are required to delete or anonymize order information within 90 days. That requirement doesn't undo the exposure, but it's the only timeline Trezor has given.
Why it's a physical risk
The exposed data can enable targeted phishing and social engineering. Delivery addresses identify households likely to own crypto, increasing the risk of physical attacks. Previous cases, including a 2025 DOJ case, show criminals using stolen databases to target crypto holders. Chainalysis reported violent crypto attacks reached $58 million in 2025 and $30 million by mid-2026. Home invasions accounted for 37% of incidents in 2026, up from 26% in 2023. The trend is clear: physical attacks on crypto holders are on the rise.
What Trezor recommends
Industry leaders recommend reducing personal information exposure, using aliases, unique passwords, hardware MFA, and non-residential delivery. For now, the company advises anyone who bought a hardware wallet to use a non-residential delivery address going forward and to be alert for phishing attempts. Trezor hasn't said whether it will change fulfillment partners, but the advice is straightforward.




