Trezor's shipping provider ShipMonk suffered a data breach that exposed order information for 13,689 hardware wallet customers. The company says its own systems were not compromised, and no wallet keys or backups were affected.
What the breach exposed
The breach exposed names, email addresses, phone numbers, and shipping addresses for 11,742 customers. Another 1,947 customers had their names, cities, and email addresses exposed, along with order numbers. The affected orders were placed between May 10 and August 8, 2026. Customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were impacted. Trezor said a 90-day data storage policy limited the exposure to recent orders.
No impact on wallets
Trezor confirmed that hardware wallets, private keys, and wallet backups were not affected. The company has contacted all affected customers individually. The breach was limited to ShipMonk's systems, not Trezor's own infrastructure.
Phishing warnings
Trezor warned customers to be wary of phishing attempts and to treat any suspicious communications with caution. The warning drew criticism from some users, with one calling it "irl phishing" because physical addresses were exposed. A similar incident at Ledger's e-commerce partner Global-e was used for phishing scams, highlighting the risk.
A history of third-party breaches
This isn't the first time Trezor customers have been caught up in a third-party breach. In 2022, a MailChimp breach led to phishing emails. In 2024, a breach of a third-party support ticketing portal exposed names and emails of about 66,000 users.
What Trezor is doing next
Trezor is investigating the breach and plans to introduce an Anonymous Delivery option with neutral packaging and automatic deletion of shipping identifiers. The company hasn't given a timeline for when that option will be available.




