The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed

A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.

trezor hack
|
8 min read
Share:
Categories: Hacks & Security

As of September 30, 2026: a second wave with roughly 67,000 more affected customers

The figure of 13,689 affected customers that this article is about is out of date. On September 4, 2026, Trezor updated its statement on the incident: on September 2, ShipMonk reported that the breach was larger than previously stated. It also contained order data from the earlier cooperation between November 2019 and August 2021, although Trezor says it repeatedly received written confirmation that this data had been deleted. Roughly 67,000 more customers in the US are affected, each with name, email address, phone number, shipping address and order number.

The same rule applies as for the first wave: Trezor emailed all affected customers directly, and anyone who did not receive such an email is not affected, according to the manufacturer. Trezor says the devices themselves are secure; the risk lies in fake emails, calls and letters that use the leaked data. How to tell genuine notifications from fake ones is explained in Trezor data breach: am I affected and what should I do now?.

The sections below reflect the situation as of August 13, 2026.

Trezor confirmed on August 13, 2026 that one of its shipping providers suffered a data breach that exposed the personal order details of thousands of hardware wallet buyers. No private keys were touched and no device was compromised, but the leaked data set is arguably the most dangerous kind in crypto: a verified list of people who own a hardware wallet, complete with the address where it was delivered.

Trezor Hack: What exactly happened in the Trezor ShipMonk data breach?

On Monday, August 10, 2026, logistics partner ShipMonk told Trezor that an unauthorized actor had accessed systems containing customer order data. Trezor disclosed the incident publicly three days later, on August 13.

ShipMonk is the fulfilment partner that stores Trezor products and ships parcels to customers in the US, UK and several other markets. To deliver a package, it holds the recipient name, shipping address, phone number, email address and order number. That is exactly the data set that was exposed.

The numbers Trezor published break down as follows:

  • 11,742 customers with full exposure: name, email, phone number and shipping address
  • 1,947 customers with partial exposure: name, city and email
  • 13,689 customers affected in total

The investigation is still ongoing. Trezor says ShipMonk has secured the affected systems and hardened its security since the incident.

Who is affected by the Trezor customer data leak?

The breach is limited to new customers who received an order between May 10 and August 8, 2026 in seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

Anything older was already gone. Trezor enforces a 90-day data retention policy and contractually requires fulfilment partners to delete or anonymize order data 90 days after delivery. That single policy is the reason the exposure stopped at roughly 13,700 people instead of every buyer in the company's history.

There is one clean test for whether you are affected. Trezor emailed every exposed customer directly from help@trezor.io. If that email is not in your inbox, you are not on the list. Worth noting given what comes next: scammers will absolutely impersonate that notification email in the coming days.

Was Trezor itself hacked and are the devices still safe?

No, and yes. This is a supply chain and vendor breach, not a wallet breach.

Trezor's own systems were not compromised. No private keys, wallet backups, seed phrases or firmware were involved, and no funds are at risk from the incident itself. The hardware did its job. The weak point was the commercial layer around the product, not the product.

That distinction matters technically, but it offers limited comfort in practice. Attackers now hold infrastructure-grade targeting data: a fresh list of confirmed crypto holders matched to real home addresses and phone numbers. An email leak is a nuisance. A name plus a home address plus a phone number identifies a specific person at a specific door as someone who very likely holds cryptocurrency.

Trezor also confirmed this is the first breach since the company was founded in 2013 to expose customer phone numbers and shipping addresses. A separate January 2024 incident at a third-party support portal exposed contact details of nearly 66,000 users, but not physical addresses.

Why is this data leak more dangerous than a typical password breach?

Because the crypto industry already has a playbook for what happens next, and it has been running since 2020.

When roughly 272,000 Ledger customer records including names, addresses and phone numbers were published following that company's 2020 e-commerce breach, the fallout never really ended. Victims reported waves of phishing emails and SMS, counterfeit hardware wallets mailed to their homes in 2021, physical letters with malicious QR codes, and phone calls from people who spoke as though they knew them personally. Some received ransom demands with threats of violence.

The physical risk is no longer theoretical. CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method. Chainalysis put the amount stolen through violent attacks at more than $30 million over the same period, on pace to pass 2025's full-year total of roughly $58 million.

Vendors keep proving to be the weakest link in this chain. Ledger's payment processor Global-e leaked customer order data in January 2026, and within days attackers were sending phishing emails announcing a fake Ledger and Trezor merger, personalized with the leaked order details. One uncomfortable detail on ShipMonk: the provider holds SOC 2 Type II certification, an audited security standard, and was breached regardless.

What should Trezor customers do right now?

Trezor's guidance is short, and the industry track record says it works:

  • Never enter your wallet backup or seed phrase on any website, ever. No legitimate company will ask for it, including Trezor.
  • Treat urgency as a red flag. Any message demanding immediate action or asking for personal information should be assumed hostile until proven otherwise.
  • Cross-reference everything against official Trezor channels, the official blog and verified social accounts. Type URLs manually rather than clicking links.
  • Expect contact across every channel, not just email. Fake phone calls, SMS, physical letters and impersonation of banks, exchanges or Trezor itself are all on the table.
  • Consider your physical security posture if your full address was exposed. Discussing holdings publicly, especially alongside a real identity, becomes materially riskier.

Anyone who wants to check status or raise a concern can contact Trezor support directly through the official site.

What is Trezor's Anonymous Delivery option?

Trezor says it is accelerating an Anonymous Delivery option designed to break the link between a hardware wallet purchase and a real world identity. Under the planned system, orders would use:

  • A dedicated checkout process
  • A nickname or label ID instead of a real name
  • Automated parcel locker pickup
  • Unbranded packaging with a generic sender label, with the carrier receiving only an email or SMS pickup PIN
  • Automatic deletion of shipping identifiers after delivery

Trezor is targeting availability in the EU by September 2026 and in the US by the end of 2026, and describes the project as a top priority.

In the meantime, the company suggests ordering with an email address not linked to your real identity, paying with crypto or a disposable virtual card rather than a credit card, and using a P.O. Box where practical.

Frequently asked questions about the Trezor data breach

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.

Related articles

Which topics should we dive deeper into?

Select what genuinely interests you. Your picks feed directly into our editorial planning.

Crypto news that's actually worth your time.

Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.

Subscribe

More on this topic

View All

More from CryptoTicker