Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.




Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
As of September 30, 2026: a second wave with roughly 67,000 more affected customers
The figure of 13,689 affected customers that this article is about is out of date. On September 4, 2026, Trezor updated its statement on the incident: on September 2, ShipMonk reported that the breach was larger than previously stated. It also contained order data from the earlier cooperation between November 2019 and August 2021, although Trezor says it repeatedly received written confirmation that this data had been deleted. Roughly 67,000 more customers in the US are affected, each with name, email address, phone number, shipping address and order number.
The same rule applies as for the first wave: Trezor emailed all affected customers directly, and anyone who did not receive such an email is not affected, according to the manufacturer. Trezor says the devices themselves are secure; the risk lies in fake emails, calls and letters that use the leaked data. How to tell genuine notifications from fake ones is explained in Trezor data breach: am I affected and what should I do now?.
The sections below reflect the situation as of August 13, 2026.
Trezor confirmed on August 13, 2026 that one of its shipping providers suffered a data breach that exposed the personal order details of thousands of hardware wallet buyers. No private keys were touched and no device was compromised, but the leaked data set is arguably the most dangerous kind in crypto: a verified list of people who own a hardware wallet, complete with the address where it was delivered.
Trezor Hack: What exactly happened in the Trezor ShipMonk data breach?
On Monday, August 10, 2026, logistics partner ShipMonk told Trezor that an unauthorized actor had accessed systems containing customer order data. Trezor disclosed the incident publicly three days later, on August 13.
ShipMonk is the fulfilment partner that stores Trezor products and ships parcels to customers in the US, UK and several other markets. To deliver a package, it holds the recipient name, shipping address, phone number, email address and order number. That is exactly the data set that was exposed.
The numbers Trezor published break down as follows:
- 11,742 customers with full exposure: name, email, phone number and shipping address
- 1,947 customers with partial exposure: name, city and email
- 13,689 customers affected in total
The investigation is still ongoing. Trezor says ShipMonk has secured the affected systems and hardened its security since the incident.
Who is affected by the Trezor customer data leak?
The breach is limited to new customers who received an order between May 10 and August 8, 2026 in seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Anything older was already gone. Trezor enforces a 90-day data retention policy and contractually requires fulfilment partners to delete or anonymize order data 90 days after delivery. That single policy is the reason the exposure stopped at roughly 13,700 people instead of every buyer in the company's history.
There is one clean test for whether you are affected. Trezor emailed every exposed customer directly from help@trezor.io. If that email is not in your inbox, you are not on the list. Worth noting given what comes next: scammers will absolutely impersonate that notification email in the coming days.
Was Trezor itself hacked and are the devices still safe?
No, and yes. This is a supply chain and vendor breach, not a wallet breach.
Trezor's own systems were not compromised. No private keys, wallet backups, seed phrases or firmware were involved, and no funds are at risk from the incident itself. The hardware did its job. The weak point was the commercial layer around the product, not the product.
That distinction matters technically, but it offers limited comfort in practice. Attackers now hold infrastructure-grade targeting data: a fresh list of confirmed crypto holders matched to real home addresses and phone numbers. An email leak is a nuisance. A name plus a home address plus a phone number identifies a specific person at a specific door as someone who very likely holds cryptocurrency.
Trezor also confirmed this is the first breach since the company was founded in 2013 to expose customer phone numbers and shipping addresses. A separate January 2024 incident at a third-party support portal exposed contact details of nearly 66,000 users, but not physical addresses.
Why is this data leak more dangerous than a typical password breach?
Because the crypto industry already has a playbook for what happens next, and it has been running since 2020.
When roughly 272,000 Ledger customer records including names, addresses and phone numbers were published following that company's 2020 e-commerce breach, the fallout never really ended. Victims reported waves of phishing emails and SMS, counterfeit hardware wallets mailed to their homes in 2021, physical letters with malicious QR codes, and phone calls from people who spoke as though they knew them personally. Some received ransom demands with threats of violence.
The physical risk is no longer theoretical. CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method. Chainalysis put the amount stolen through violent attacks at more than $30 million over the same period, on pace to pass 2025's full-year total of roughly $58 million.
Vendors keep proving to be the weakest link in this chain. Ledger's payment processor Global-e leaked customer order data in January 2026, and within days attackers were sending phishing emails announcing a fake Ledger and Trezor merger, personalized with the leaked order details. One uncomfortable detail on ShipMonk: the provider holds SOC 2 Type II certification, an audited security standard, and was breached regardless.
What should Trezor customers do right now?
Trezor's guidance is short, and the industry track record says it works:
- Never enter your wallet backup or seed phrase on any website, ever. No legitimate company will ask for it, including Trezor.
- Treat urgency as a red flag. Any message demanding immediate action or asking for personal information should be assumed hostile until proven otherwise.
- Cross-reference everything against official Trezor channels, the official blog and verified social accounts. Type URLs manually rather than clicking links.
- Expect contact across every channel, not just email. Fake phone calls, SMS, physical letters and impersonation of banks, exchanges or Trezor itself are all on the table.
- Consider your physical security posture if your full address was exposed. Discussing holdings publicly, especially alongside a real identity, becomes materially riskier.
Anyone who wants to check status or raise a concern can contact Trezor support directly through the official site.
What is Trezor's Anonymous Delivery option?
Trezor says it is accelerating an Anonymous Delivery option designed to break the link between a hardware wallet purchase and a real world identity. Under the planned system, orders would use:
- A dedicated checkout process
- A nickname or label ID instead of a real name
- Automated parcel locker pickup
- Unbranded packaging with a generic sender label, with the carrier receiving only an email or SMS pickup PIN
- Automatic deletion of shipping identifiers after delivery
Trezor is targeting availability in the EU by September 2026 and in the US by the end of 2026, and describes the project as a top priority.
In the meantime, the company suggests ordering with an email address not linked to your real identity, paying with crypto or a disposable virtual card rather than a credit card, and using a P.O. Box where practical.
Frequently asked questions about the Trezor data breach
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.
Related articles
- Trezor Data Breach: Am I Affected and What Should I Do Now?
- SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
- Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 1, 2026 7:27 AM

Clipboard Attack: How Malware Swaps the Wallet Address You Copied
A clipper replaces the receiving address between copying and pasting with the attacker’s, and your wallet’s checksum notices nothing. What Microsoft and the Federal Office for Cybersecurity have documented, and which check really makes the attack come to nothing.
August 25, 2026 10:31 PM

Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 10, 2026 1:14 PM

Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
An alleged security warning to wallet customers travelled through the manufacturer's genuine sending channel and passed every technical authenticity check. The test that still holds costs you four minutes.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
December 28, 2018 3:02 PM

How To Use a Trezor Wallet?
Trezor is a hardware wallet which gives exceptional security for managing Bitcoin and other cryptocurrencies private keys.It incorporates and deposits personal keys securely and enables users to carry trade without an Internet link. Trezor grants its users with numerous benefits, […]
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 22, 2019 9:55 AM

Here’s why you should skip Facebook’s Crypto: Instagram Data Breach
It’s practically similar to stating the sky is blue yet we have another Facebook Data Leak close by influencing a huge number of clients. This time around, it includes the contact data of in excess of 49 million Instagram Accounts […]
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
More from CryptoTicker

