Trezor has revealed that personal details of 13,689 customers were exposed after a breach linked to its shipping partner, ShipMonk.

Summary

  • ShipMonk’s security incident compromised personal information of 13,689 customers of Trezor.
  • Data such as names, email addresses, phone numbers, and shipping details were accessed.
  • Trezor confirmed that its own systems and hardware wallets remain secure.
  • Customers affected have been cautioned about the potential for sophisticated phishing schemes.
  • The company aims to introduce an Anonymous Delivery service in the EU by September 2026, followed by a U.S. launch by the end of the same year.

Trezor issued a security report on August 13, stating that ShipMonk informed them on August 10 about unauthorized access to customer order data. An investigation into the breach is currently ongoing.

The incident affected customers who placed orders with Trezor between May 10 and August 8 across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. Trezor has reassured that its own systems were not impacted and that its hardware wallets remain safe.

Among those affected, 11,742 individuals had their names, email addresses, phone numbers, and shipping details breached. An additional 1,947 customers had partial information compromised, encompassing their names, cities, and email addresses.

Additionally, order numbers were included in the data managed by ShipMonk for shipping purposes, according to Trezor’s explanation of the breach.

ShipMonk Breach Affects Trezor Order Data

ShipMonk functions as a logistics provider for Trezor, managing product storage and deliveries in various regions. To facilitate shipping, the company requires customer names, addresses, phone numbers, and emails.

Trezor noted that the number of exposed customers was limited due to its 90-day data retention policy, which is also enforced among its fulfillment partners. Customer details tied to older orders had either been deleted or anonymized, thus not being available in the affected ShipMonk systems.

This 90-day timeframe ensures all aspects of the order process—delivery, returns, refunds, and replacements—are covered. Once this period lapses, customer information regarding purchases is eliminated or anonymized as Trezor no longer needs such details for fulfillment.

Affected customers have been contacted via emails from [email protected]. Customers who did not receive any notifications are not considered impacted by the incident, according to Trezor.

ShipMonk has since fortified its security measures on the affected systems, as stated by Trezor. Both companies are collaborating to investigate the cause of the breach and ascertain the specifics of the accessed information.

This incident marks the first occurrence since Trezor’s establishment in 2013 in which customer phone numbers and shipping addresses were compromised.

“We fully recognize the gravity of this situation and the potential risks it poses to our customers, and we sincerely apologize to those who have been affected,” Trezor stated.

Trezor Alerts Customers to Phishing Risks

Despite Trezor’s wallet devices and infrastructure remaining intact, the company cautioned that the exposed personal data could be misused for more convincing phishing scams.

Cybercriminals might leverage a customer’s name, phone number, email, or home address to impersonate Trezor, a cryptocurrency exchange, or a bank, leading to fraudulent interactions via emails, phone calls, or letters.

Past attacks have targeted hardware wallet users by exploiting personal information in seemingly legitimate communications. In February, crypto.news reported on counterfeit letters sent to Trezor and Ledger users, directing them to phishing sites through QR codes.

These letters informed recipients of necessary authentication checks or transaction verifications, creating urgency with warnings of potential wallet functionality issues. The linked phishing sites solicited 12-, 20-, or 24-word recovery phrases, enabling attackers to access wallets if submitted.

Physical letters raise additional concerns when attackers already possess the victim’s mailing address. An April 2025 Ledger phishing campaign similarly involved deceptive letters with Ledger branding, a business address, and individual reference numbers.

Victims in that instance were instructed to scan a QR code and provide their 24-word recovery phrase under pretenses of needing a security update.

Trezor urges customers impacted by the ShipMonk breach to approach any communications requesting immediate actions or personal information cautiously. The company recommended verifying messages against its official communications and advised against providing backup information via websites or to other individuals.

Past Incidents Have Also Resulted in Phishing Alerts

Trezor has previously experienced customer data exposures via third-party services, though it emphasized that the ShipMonk incident is the first involving leaked phone numbers and shipping addresses.

In January 2024, an unauthorized entity accessed a third-party support ticket portal utilized by Trezor, potentially exposing contact information for around 66,000 customers who had engaged with customer support since late 2021.

During that incident, Trezor notified those affected and confirmed that digital assets had not been compromised, as it involved an external support system rather than Trezor’s hardware wallets.

Another phishing method emerged in June 2025 when attackers exploited Trezor’s contact form by submitting targeted users’ email addresses in support requests. This generated legitimate automated replies, making the subsequent phishing messages seem more credible.

Trezor stated that its email system was not breached and that the contact form remained secure, emphasizing that attackers exploited the support workflow to fabricate fraudulent messages that appeared linked to valid communications.

Hardware security remains under scrutiny as well. In June, Trezor and Tropic Square disclosed a chip flaw affecting the TROPIC01 Secure Element used within the Trezor Safe 7, identified during a third-party audit by researchers from Ledger Donjon.

Using laser fault injection in a controlled environment, Ledger Donjon was able to extract certain secrets from the chip and bypass firmware signature checks. Trezor explained that this attack required physical access and specialized tools; however, two other security layers continue to protect wallet access. Users were not required to take any actions.

In contrast, the ShipMonk incident involved order data held by a fulfillment partner rather than the hardware or software component responsible for safeguarding private keys.

Trezor Introduces Anonymous Delivery Initiative

In light of the recent events, Trezor is also outlining methods customers can employ to minimize the personal data linked to future hardware wallet acquisitions.

The company advises using an email that is not tied to a primary identity and suggests opting for cryptocurrency payments instead of credit cards. Where feasible, customers are encouraged to utilize a P.O. Box to limit their home address exposure, although identification mandates and postal service records may still apply.

Trezor is also preparing to launch an Anonymous Delivery service aimed at minimizing the amount of customer information retained during hardware wallet shipments.

This forthcoming system will feature a dedicated checkout process, locker collection, neutral packaging, and generic sender information. Shipping identifiers will be automatically deleted post-delivery.

Trezor has announced plans to offer Anonymous Delivery in the European Union by September 2026, with a rollout in the U.S. expected by the end of that same year.

Share.