
Hardware crypto wallet company Trezor warned Thursday of heightened phishing risk after a breach at third-party logistics provider ShipMonk exposed personal information belonging to 13,689 customers, including names, addresses, phone numbers and email addresses.
There was no evidence that wallet backups, cryptocurrency holdings, or Trezor’s own systems were compromised, but the company cautioned the leaked data could be used to craft more convincing scams targeting affected users.
Sponsored
What Happened in the Trezor Data Breach?
ShipMonk notified Trezor on August 10 that an unauthorized actor had accessed systems containing customer data. ShipMonk provides logistics services for Trezor, including storing and shipping its products in several markets.
Of the 13,689 affected customers, 11,742 had full names, email addresses, phone numbers and shipping addresses exposed. The remaining 1,947 customers had partial information exposed, including names, city names and email addresses.
The affected records primarily involved new-customer orders placed between May 10 and August 8, 2026, and shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor said its 90-day data-retention policy with logistics partners helped limit the scope of the incident because older order information had already been deleted or anonymized.
The company is still working with ShipMonk to determine the exact exposure window for the 1,947 customers whose partial information was affected.
Trezor said affected customers were individually notified by email from help@trezor.io. Customers who did not receive a notification are not affected, according to the company.
Trezor Systems and Wallets Were Not Compromised
Trezor said there is no indication that its internal systems, hardware wallets or wallet backups were compromised in the incident.
The company urged customers never to enter their wallet backup online or share it with anyone.
The main risk from the breach is instead the personal information that could be used to impersonate Trezor or create more convincing fraudulent messages.
Why the Exposed Data Matters
Names, phone numbers, email addresses and shipping information can provide attackers with additional context for targeted phishing campaigns.
A message that references a customer’s name, recent Trezor purchase or delivery details may appear more credible than a generic scam. Attackers could then attempt to persuade victims to disclose sensitive information, click malicious links or reveal their wallet backup.
Trezor users should therefore be particularly cautious about unsolicited messages claiming to involve wallet security, account problems, refunds, deliveries or other urgent issues.
Trezor’s Response
Trezor described the incident as the first breach since its founding in 2013 to expose customer phone numbers and shipping addresses and apologized to affected users.
The company plans to introduce an Anonymous Delivery option featuring dedicated checkout, locker pickup, neutral packaging and automatic deletion of shipping identifiers.
The company aims to launch the service in the EU by September 2026 and in the US by the end of 2026.
Trezor Has Faced Third-Party Incidents Before
The ShipMonk incident follows earlier security problems involving third-party providers.
In January 2024, unauthorized access to Trezor’s third-party support portal potentially exposed names and email addresses of about 66,000 users.
A separate Mailchimp breach in 2022 affected Trezor customers and was followed by phishing campaigns targeting cryptocurrency users.
Other hardware-wallet companies have faced similar incidents. Ledger, for example, suffered a major 2020 data breach that exposed more than 1 million email addresses and hundreds of thousands of customer records. Some of that information was subsequently used in cryptocurrency scams.
Why Could the Trezor Breach Increase Phishing Risks?
The incidents illustrate a broader security problem for hardware-wallet users: attackers do not necessarily need access to a wallet or its cryptographic keys to target its owner. Personal information obtained through a third-party breach can be enough to make a scam appear legitimate.
Dive into DailyCoin’s trending crypto scoops today:
Bitcoin OGs Are Sitting on Record Profits — and Hunting for the Bottom
Bitcoin’s Valuation Has Cooled Sharply. The $57.6K Level Now Matters