Trezor said a data breach at fulfillment partner ShipMonk exposed order information linked to 13,689 customers, while hardware wallet devices, private keys, backup seed phrases, and Trezor’s own systems were not affected.
Order details were exposed, not wallet credentials
According to Decrypt, Trezor confirmed the incident on Aug. 13 and said the breach occurred at ShipMonk, one of its shipping partners. The company said sensitive order data was exposed after the vendor incident, but Trezor’s internal systems were not breached.
Trezor said 11,742 customers had full records exposed, including names, phone numbers, email addresses, and shipping addresses. Another 1,947 customers were affected by a partial exposure involving names, cities, and email addresses.
Affected orders were created between May 10 and Aug. 8
The company said the impacted orders were created from May 10 through Aug. 8. The affected customers were located across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor also posted on X that a data breach at a shipping vendor had exposed sensitive order information.
Trezor warns users about phishing attempts
Trezor said customer funds remain safe, but warned that the main risk after the leak is phishing. The company urged users to treat unexpected phone calls, text messages, and emails with caution, and said they should never enter a wallet backup seed phrase online.
The report said this is the first time in Trezor’s 13 years of operation that customer phone numbers and addresses have been exposed. It also pointed to the 2020 Ledger leak of 272,000 customer records, after which some users faced extortion and even physical threats.
As described in the report, the most immediate danger from leaked personal information may not be direct theft of wallet funds, but fraudulent messages built around a customer’s real name and address to trick them into handing over a seed phrase.

