Aug 14, 2026
Policy

Trezor ShipMonk data breach exposed details of 13,689 customers

Trezor says a ShipMonk breach exposed delivery and contact data for 13,689 buyers, creating phishing risks while wallets remain secure.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Trezor ShipMonk data breach exposed details of 13,689 customers
Photo: The Register

Trezor says a breach at fulfillment provider ShipMonk exposed personal information tied to 13,689 customers, while the hardware-wallet maker’s own systems and devices were not compromised. The Trezor ShipMonk data breach puts names, delivery details and contact information in the hands of an unauthorized party, according to Trezor, creating an opening for targeted scams against crypto holders.

The company said 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. A further 1,947 had names, home cities and email addresses exposed. Trezor said it has directly notified affected customers.

The affected buyers are in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. Trezor initially described the affected group as customers whose orders fell within the 90 days before Aug. 8, but said it is checking with ShipMonk whether older orders may also be included. The full scope beyond that period is therefore unresolved.

What information was exposed in the Trezor ShipMonk data breach?

  • For 11,742 customers: name, email address, phone number and shipping address.
  • For 1,947 customers: name, city and email address.
  • Trezor said its wallet devices, company systems and services remain secure.

ShipMonk stores and ships Trezor products and handles the customer data required to complete deliveries, according to Trezor. Trezor said ShipMonk is subject to its 90-day retention policy, under which partners are required to delete or anonymize order data after that period.

The distinction matters: the reported incident concerns commerce and logistics records, rather than a compromise of wallet hardware or the cryptographic protections used by those devices. But an address tied to a crypto-wallet purchase, combined with a phone number and email address, can make an impersonation attempt more credible.

Trezor warned that affected customers could receive phishing messages, fraudulent calls or mailed communications impersonating Trezor, a bank or a crypto exchange. It told customers to verify communications through its official channels and said they should not enter a wallet backup on a website or disclose it to another party.

In comments reported by CoinDesk, Trezor said it had no confirmed indication that the exposed information had been published, shared or put up for sale, and it was not aware of scams or hacking attempts connected to the incident at that time. The company also said orders placed through Amazon were not affected because they are fulfilled by another partner.

Trezor said this is the first incident in its history, which began in 2013, to expose customer phone numbers and shipping addresses. It is developing an Anonymous Delivery option that it says will send products to automated lockers under a nickname or label ID, with unbranded packaging. Trezor has said it expects to launch that service in the EU in September and in the US by year-end.

This story draws on original reporting from The Register.

More from Policy

All Policy →