Trezor said a breach at third-party shipping provider ShipMonk exposed personal and order data belonging to 13,689 recent customers, including names and contact details that could be used in targeted phishing attacks. The exposure of shipping addresses also creates a potential physical-security risk because it links named customers to recent Trezor orders.
Two sets of customer records were exposed
In its disclosure, Trezor said 11,742 customers had their full name, email address, phone number and shipping address exposed. Another 1,947 customers had their name, city and email address exposed.
The affected orders were delivered between May 10 and Aug. 8 to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said ShipMonk informed it on Aug. 10 that systems containing customer data had been accessed without authorization. The investigation is ongoing.
Trezor says its own systems were not compromised
The company said its own systems were not affected and that Trezor devices remain secure. It also said all affected customers were contacted separately by email. According to the notice, customers who did not receive an email from help@trezor.io were not impacted.
Trezor warned recipients to expect more sophisticated phishing attempts. It said scammers could use the exposed information in fake emails, phone calls and letters, or impersonate Trezor, a bank or a crypto exchange. The company told customers never to enter a wallet backup on a website, never to share it with anyone, and to verify communications through Trezor’s official channels.
Shipping addresses add a physical-security concern
The exposed records identify people who recently received an order from Trezor and, for most of those affected, include the address where the package was delivered. That combination can make a fake support message more convincing. It could also help a criminal choose a physical target.
A public repository maintained by Jameson Lopp tracks known physical attacks against bitcoin and crypto owners dating back to 2014, including home invasions, kidnappings, robberies and extortion. Trezor described a potential risk in its disclosure and did not report any compromise of its own systems or devices.
A 90-day retention policy limited the scope
Trezor said the scale of the breach was limited by a 90-day data-retention policy that also applies to its fulfillment partners. Its published privacy policy says names, addresses, phone numbers and email addresses used for delivery are deleted from Trezor and fulfillment-partner systems after 90 days, except in cases involving unresolved order issues.
The company said this was the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses. Trezor plans to make an Anonymous Delivery option available in the European Union by September 2026 and in the U.S. by the end of 2026. The proposed feature includes locker pickup and automatic deletion of shipping identifiers after delivery.
Order-data exposure has hit hardware-wallet customers before
Exposure of order data has repeatedly affected customers of hardware-wallet companies without necessarily compromising the wallets themselves. Ledger said a January 2026 incident at commerce provider Global-e exposed names, postal addresses, email addresses, phone numbers and order details, while leaving Ledger devices and systems unaffected.
Ledger also disclosed in 2020 that an unauthorized party accessed its ecommerce and marketing database, exposing email addresses and, for a subset of customers, names, postal addresses, phone numbers and order information.
ShipMonk has secured the affected systems
Trezor said ShipMonk has secured and hardened the affected systems while the companies work to determine exactly what happened and which data was accessed.

