Trezor has disclosed a data breach at third-party shipping provider ShipMonk that exposed personal and order data belonging to 13,689 recent customers. The compromised information includes names and contact details that could be used for targeted phishing. Trezor emphasized that its own systems and devices were not compromised in the incident.

According to Trezor's disclosure, 11,742 customers had their full name, email address, phone number, and shipping address exposed. Another 1,947 had their name, city, and email address exposed. The affected orders were delivered between May 10 and Aug. 8 to customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk informed Trezor on Aug. 10 of unauthorized access to systems containing customer data, and the investigation remains ongoing.

Trezor said it contacted all affected customers separately by email, and those who did not receive an email from [email protected] were not affected. The company warned recipients to expect more sophisticated phishing attempts, including fake emails, phone calls, and letters that impersonate Trezor, a bank, or a crypto exchange. It advised customers never to enter their wallet backup on a website or share it with anyone, and to verify messages against Trezor's official channels.

The exposed records identify people who recently received an order from Trezor and, for most of those affected, include the delivery address. This combination can make fake support messages more convincing and could also help a criminal select a physical target. A public repository maintained by Jameson Lopp lists known physical attacks against bitcoin and crypto owners dating back to 2014, including home invasions, kidnappings, robberies, and extortion. Trezor described this as a potential risk; it did not report a compromise of its systems or devices.

Trezor attributed the scope of the breach to a 90-day data-retention policy that also applies to its fulfillment partners. Its published privacy policy says names, addresses, phone numbers, and emails used for delivery are deleted from Trezor and fulfillment-partner systems after 90 days, subject to exceptions for unresolved order issues. The company said this was the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses. Trezor aims to make an “Anonymous Delivery” option available in the European Union by September 2026 and in the U.S. by the end of 2026, featuring locker pickup and automatic deletion of shipping identifiers after delivery.

Order-data exposure has repeatedly affected customers of hardware-wallet companies without necessarily compromising the wallets themselves. Ledger said a January 2026 incident at commerce provider Global-e exposed names, postal addresses, email addresses, phone numbers, and order details, while leaving Ledger devices and systems unaffected. Ledger also disclosed in 2020 that an unauthorized party accessed its ecommerce and marketing database, exposing email addresses and, for a subset of customers, names, postal addresses, phone numbers, and order information. Trezor said ShipMonk has secured and hardened the affected systems while the companies work to establish exactly what happened and which data was accessed.