Trezor Shipping Partner Data Breach Exposes 13,689 Customer Records

1 hour ago 4 sources negative

Key takeaways:

  • Phishing risk from leaked Trezor order data may accelerate adoption of multisig self-custody solutions.
  • Hardware wallet data breaches reinforce structural demand for privacy-preserving delivery and neutral packaging.
  • BTC holders migrating from exposed hardware ecosystems could reduce liquid supply, supporting prices near-term.

Trezor, one of the best-known hardware wallet manufacturers, disclosed on Thursday that a data breach at its fulfillment partner ShipMonk exposed sensitive order data belonging to 13,689 customers.

According to Trezor, ShipMonk notified the company on Monday that an unauthorized party had reached systems holding customer data. Of the affected individuals, 11,742 had full names, phone numbers, email addresses and shipping addresses exposed, while another 1,947 had names, cities and email addresses partially exposed. The impacted orders were placed between May 10 and August 8, and shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal.

Trezor stressed that its own systems were not compromised, and that no device, private key, or wallet backup was affected. It attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, which removed older orders from the exposed data. Customers who did not receive a notification email are not affected, the company said.

The hardware wallet maker warned that the leaked information could be used for phishing and social-engineering attacks. It urged customers to treat unexpected contact with suspicion and never enter a wallet backup online. Trezor noted that in 13 years it had never before experienced a breach that exposed customer phone numbers and shipping addresses.

The incident follows a 2020 breach at rival Ledger, where roughly 272,000 customers had personal details published and some later received threatening ransom demands. Security researchers at CertiK verified 52 physical attacks on crypto holders in the first half of 2026, up from 39 a year earlier, while Chainalysis estimated more than $30 million was stolen in such attacks during the same period.

The disclosure also comes amid broader hardware wallet security concerns. Ledger disclosed a breach at its e-commerce partner Global-e in January, and the recent Coldcard exploit has pushed losses toward $130 million. According to Casa, some of the 233,000 BTC—roughly $15 billion—that left long-term holder wallets around the Coldcard incident came from Ledger and Trezor owners moving funds to multi-signature setups.

Trezor said it is bringing forward an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers. The option is targeted for the European Union by September and the United States by the end of the year.

Previously on the topic:
Aug 7, 2026, 8:38 a.m.
Coinkite Coldcard Exploit Drains $100M, Firm Prepares Post-Mortem
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.