Trezor's Shipping Partner Exposed Personal Data of Nearly 14,000 Customers
A logistics vendor breach has put physical addresses, names, and contact details of Trezor hardware wallet buyers into unauthorized hands. Trezor's own systems and devices were not affected.
A security breach at ShipMonk, the third-party fulfillment company that handles order logistics for hardware wallet maker Trezor, exposed personal data belonging to 13,689 customers between May 10 and August 8, 2026. Trezor disclosed the incident on August 13. The compromised records include physical shipping addresses for the majority of those affected, a category of data that carries heightened risk for cryptocurrency holders.
Of the total affected customers, 11,742 had their full details exposed: names, phone numbers, email addresses, home or delivery addresses, and order numbers. The remaining 1,947 had partial records accessed, limited to names, cities, and email addresses. Trezor confirmed that its own infrastructure was not involved. "Our systems were not compromised, and the devices remain secure," the company said, according to reporting by Decrypt, ChainCatcher, and Odaily. ShipMonk, which warehouses and ships products for e-commerce clients including hardware manufacturers, notified Trezor after an unauthorized party accessed its customer data systems. As of publication, no public statement from ShipMonk had been located.
The countries named in Trezor's disclosure are the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor warned affected customers to expect targeted phishing attempts using the exposed data and advised them to "treat unexpected contact with suspicion and never enter a wallet backup online." In a separate warning reported by Odaily, Trezor described the anticipated attempts as "sophisticated phishing attempts." A wallet backup, also called a seed phrase, is the 12 or 24-word string that grants full access to a hardware wallet's funds. Trezor's standard guidance states that it will never request a seed phrase through any channel.
This is not Trezor's first exposure through a vendor. In April 2022, attackers breached email marketing firm MailChimp and used customer lists to send phishing messages impersonating Trezor. In January 2024, a third-party support portal was compromised, leaking contact information for 66,000 users, with at least 41 receiving direct emails soliciting seed phrases, according to Bleeping Computer. The August 2026 ShipMonk incident is at minimum the third time a Trezor vendor has been the point of failure. Each time, Trezor's own hardware and firmware remained intact. The pattern points to third-party vendor management as the company's most persistent security liability.
The stakes of a physical address leak are materially different from those of a typical email data breach. Knowing that someone purchased a hardware wallet, and knowing where they live, provides enough information to target that person for coercion or theft. Physical attacks on crypto holders have accelerated sharply in 2026. CertiK documented 52 such incidents globally in the first half of the year, up from 39 in the same period of 2025. Yellow.com Research estimates that physical coercion attacks generated at least $124 million in losses in H1 2026, with Chainalysis confirming $30 million in forced on-chain transfers under physical duress. Yellow.com estimates the true total may reach $180 to $200 million once unreported incidents are accounted for. Home invasions have overtaken kidnapping as the most common method, accounting for 34% of documented cases compared with 14% for kidnapping. Separately, phishing losses reached $311 million in January 2026 alone, according to CertiK data cited by Analytics Insight; Scam Sniffer data shows that signature phishing losses jumped 207% in January 2026 compared with December 2025, underscoring the scale of that figure. Physical mail campaigns impersonating hardware wallet brands, including both Trezor and Ledger, have also appeared as a notable threat vector in early 2026, targeting buyers by name at their delivery addresses, which is precisely the data now exposed.
For users outside the seven named countries, the immediate risk is limited but the context matters. Hardware wallet adoption is growing across South Asia and Sub-Saharan Africa, driven by currency instability, banking access gaps, and demand for self-custody. Nigeria processed over $92 billion in crypto value between July 2024 and June 2025, according to Chainalysis data. Kenya has more than 4 million active crypto wallet users, according to Tangem. As Trezor's distribution expands into these markets, its logistics partners will accumulate shipping data for buyers in those regions, creating the same class of vendor exposure documented in this breach. The Asia-Pacific hardware wallet market is projected to grow at a compound annual rate of 26.1% through 2035, according to Straits Research. Users in these regions who have placed Trezor orders in the affected window should treat any inbound communication referencing their order, wallet, or a required security action as suspect by default.
Trezor has announced a privacy-oriented shipping feature called Anonymous Delivery, which will route orders through parcel lockers, use generic packaging, and automatically delete address data after fulfillment. The EU rollout is scheduled for September 2026, with US availability targeted before year-end. No timeline has been announced for other regions. Until that option is available, Trezor's advisory guidance suggests that buyers in markets without Anonymous Delivery coverage may reduce exposure by purchasing through local resellers rather than shipping directly from Trezor, and by using a pickup address rather than a home address wherever possible.