Trezor confirmed a data breach at its shipping provider ShipMonk, exposing personal details of about 13,689 buyers. The breach affects orders shipped between May 10 and Aug 8 across seven countries. Trezor says its own systems and devices were not compromised.
What ShipMonk exposed
The exposure isn't uniform. Trezor says 11,742 buyers had full exposure — name, email, phone number and shipping address. Another 1,947 had partial exposure, limited to name, city and email. That's a lot of personal data floating around, and it's exactly the kind of information that makes phishing attempts more convincing.
How the breach came to light
ShipMonk informed Trezor of unauthorized access on Aug 10. The investigation is still ongoing, and neither company has said how the intruder got in or how long they had access. Trezor's own hardware wallets and firmware were not touched, but the logistics partner turned out to be the weak link.
What Trezor is telling customers
Trezor has already emailed the affected buyers and says it will provide further updates. The company's advice is blunt: treat any unsolicited outreach with suspicion, and never share your recovery seed. That last part is worth repeating — no legitimate support team will ever ask for it.
The supply-chain risk
This incident is a reminder that a crypto hardware vendor's security is only as strong as its least careful partner. Trezor's own systems held up, but a shipping provider with access to customer data became a hole. For buyers, the immediate risk is social engineering — someone with your name, address and order history can craft a very believable fake email.
The investigation is still open, and Trezor says it will keep customers posted. In the meantime, if you're one of the 13,689, assume your details are out there and act accordingly.




