Trezor says data breach exposed details of nearly 14,000 wallet customers

Trezor says data breach exposed details of nearly 14,000 wallet customers

N
News Editor
2026-08-13 16:52:05
Hardware wallet maker Trezor said a data breach at one of its shipping and fulfillment providers exposed customer order data affecting 13,689 users in seven countries. The company said the incident involved customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order in the 90 days before Aug. 8. According to Trezor, 11,742 customers had their names, email addresses, phone numbers, and shipping addresses exposed, while another 1,947 had their names, cities, and email addresses leaked. Trezor said its own systems and devices remain secure, but warned that affected users could face more phishing attempts. In an email to Bitcoin Magazine, parent company SatoshiLabs said the breach stemmed from unauthorized access at third-party fulfillment partner ShipMonk. The company said scammers could use the leaked data to send fake emails, make fraudulent phone calls, mail deceptive letters, or impersonate banks, crypto exchanges, or Trezor itself. SatoshiLabs said the investigation is ongoing. The report also places the incident in a broader pattern of customer-data and hardware-wallet security problems, citing previous breaches involving Ledger and a separate hacking case tied to Coinkite’s Coldcard devices.

Trezor said a data breach at one of its shipping providers exposed customer order data for nearly 14,000 users.

In a post on X on Thursday, the hardware wallet maker said 13,689 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were affected. The company said those users had received an order in the 90 days prior to Aug. 8.

Trezor wrote: 「We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…」 The post was dated Aug. 13, 2026.

What customer data was exposed

The Prague, Czech Republic-based company said its own systems and devices remain secure. It added that affected customers could see an increase in phishing attempts.

Trezor said 11,742 customers had their names, email addresses, phone numbers, and shipping addresses leaked. Another 1,947 customers had only their names, cities, and email addresses exposed.

The company also said: 「We are deeply sorry to the community and those affected.」

ShipMonk named as the third-party partner involved

In an email to Bitcoin Magazine, SatoshiLabs, Trezor’s parent company, said its third-party fulfillment partner ShipMonk had experienced unauthorized access to systems containing customer data.

SatoshiLabs said scammers could use the leaked information to send fake emails, place fraudulent phone calls, mail deceptive letters, or impersonate banks, crypto exchanges, or even Trezor. The company said it is continuing to investigate the incident.

Part of a wider string of hardware wallet security incidents

Trezor is one of the more widely used Bitcoin hardware wallet products and also supports storage for other cryptocurrencies. The report noted that Bitcoin users’ personal data has been targeted before.

In 2020, an unauthorized party accessed hardware wallet maker Ledger’s e-commerce and marketing database, leaking more than 1 million email addresses and the personal contact data of nearly 10,000 customers.

At the start of this year, customers also reported receiving emails from Global-e, Ledger’s payment partner, saying that a breach in its cloud systems had leaked sensitive customer data.

The report also referenced a separate case involving Coinkite’s Coldcard products. Hackers began draining $111 million in Bitcoin from the popular Coldcard hardware wallets at the end of last month. As investigations continue, the amount stolen could be higher, with some estimates putting the real figure above $130 million.

According to the report, the theft was still ongoing, with Bitcoin users and Coinkite urging customers to move their funds as hackers continued to drain digital assets from later devices.

The story first appeared in Bitcoin Magazine and was written by Mathew Di Salvo.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
160

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.