Trezor Shipping Partner Breach Exposes 13,600 Customer Addresses

Close-up of Scrabble tiles spelling 'data breach' on a blurred background

In brief

  • ShipMonk notified Trezor of unauthorized access to customer shipping data from May 10 to August 8
  • 13,689 customers affected across US, UK, Sweden, Colombia, Brazil, Italy, and Portugal
  • Trezor's systems, devices, and private keys remain uncompromised
  • Trezor launching Anonymous Delivery option with locker pickup and neutral packaging by year-end

The Breach Scope

ShipMonk notified Trezor on Monday of the unauthorized access to its systems. Some 11,742 customers had their full details taken and another 1,947 had names, cities and email addresses exposed, totaling 13,689 affected customers. Those affected placed orders between May 10 and August 8 and had them shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal.

The breach hits at a critical vulnerability: home addresses and phone numbers tied to hardware wallet owners. This data is exactly what attackers need to orchestrate phishing campaigns or physical theft.

What Trezor Says

Trezor said its own systems were not compromised and that no device, private key or wallet backup was touched. The company attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery. In 13 years, the company added, it has never before had a breach exposing customer phone numbers and shipping addresses.

That's the silver lining. No wallet backups leaked. No private keys exposed. But the shipping data alone poses real danger.

The Larger Context

The Trezor breach arrives as crypto holders face escalating physical threats. After roughly 272,000 Ledger customers had names, addresses and phone numbers published in 2020, some began receiving ransom demands threatening violence. CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method. Chainalysis put the sum stolen at more than $30 million over the same period.

The Ledger precedent matters. Ledger disclosed a breach at its own e-commerce partner, Global-e, in January. Hardware wallet makers can't fully insulate themselves from third-party risk.

What Customers Should Do

Trezor's warning concerns phishing, and it advises customers to treat unexpected contact with suspicion and never to enter a wallet backup online. Affected customers should expect social engineering attempts and should verify any support request through official channels only.

Trezor is moving to address the root problem. The company said it is bringing forward an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers, targeting the European Union by September and the United States by the end of the year. It's a step toward decoupling hardware wallet ownership from physical identity.