PRAGUE, Aug. 13, 2026
Trezor said a data breach at its shipping provider ShipMonk exposed customer order information for about 13,689 people, including full names, shipping addresses, phone numbers and email addresses for 11,742 customers. The hardware-wallet company said its own systems, devices, private keys and wallet backups were not compromised, but warned that exposed buyers could face more tailored phishing.
The incident was disclosed Aug. 13 after ShipMonk told Trezor on Aug. 10 about unauthorized access to systems containing customer data. Trezor said the full-exposure group covers recent direct-store orders delivered in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal, generally within the 90 days before Aug. 8.
Another 1,947 people had a more limited exposure of name, city and email address, according to the Trezor incident notice. Trezor says that group may include older orders while it verifies the timing with ShipMonk. The company has contacted affected customers separately; it says people who did not receive a notice from [email protected] are not part of the incident.
The breach is a personal-safety and social-engineering risk, not a reported on-chain theft. A dedicated loss-impact check found no confirmed theft, drained wallet, victim loss total, affected-wallet count or on-chain transaction evidence tied to this disclosure as of 21:36 Casablanca time. That distinction matters, but an address linked to a hardware-wallet purchase can make a phishing message, call or mailed letter unusually persuasive.
Bitcoin traded near $63,415 when checked on Aug. 13, down from about $64,984 on July 15, according to CoinGecko market data. The price move does not establish a connection to the disclosure; the Trezor event is about customer information and attempted social engineering rather than a Bitcoin network or market failure.
Bitcoin
BTCTrezor Says ShipMonk Exposed 11,742 Full Customer Records
The company said ShipMonk held the data to fulfill deliveries. For the 11,742 customers in the full-exposure group, that information included a name, email, phone number and physical shipping address. Trezor’s more detailed FAQ also says ShipMonk retains the order number needed for delivery.
Trezor described its 90-day retention rule as the reason the exposure is limited. Its privacy policy says completed or canceled e-shop order data is deleted after 90 days, with exceptions for ongoing order problems, while invoice data is kept separately for legal requirements. The company said it requires the same deletion or anonymization standard from fulfillment partners.
That policy does not erase the risk for the people whose data was still in ShipMonk’s systems. The combination of a real name, address, phone number, email and an apparent hardware-wallet purchase gives an attacker enough context to impersonate a delivery firm, bank, exchange or Trezor support with a higher chance of being believed.
The disclosure is separate from the seed-generation flaw and documented thefts in the recent Coldcard incident. Trezor has not reported a device weakness, exposed seed phrase or unauthorized transfer here. It says ShipMonk secured the affected systems and hardened security, while the companies continue to investigate what happened.
No Wallets or Keys Reported Compromised, but Phishing Risk Rises
Trezor’s clearest message is that an exposed address does not itself give anyone access to a wallet. Its notice says its systems were not compromised and Trezor devices remain secure. A recovery phrase or wallet backup, not a shipping record, is the secret that can recreate a wallet and authorize a theft.
But attackers do not always need a technical break. Earlier this year, BleepingComputer documented postal phishing letters that used urgent device-verification claims and QR codes to send hardware-wallet users to seed-phrase phishing sites. The reporting said those sites ultimately asked people to enter their recovery words.
That is why an apparent support message should not be treated as trustworthy just because it includes a correct address or order detail. Trezor says customers should be suspicious of communications demanding immediate action or personal information and should cross-check messages with official company channels. Its scams and phishing guidance is unequivocal: a user should never enter a wallet backup on a website or share it with anyone.
The same operational lesson applied in Daily Crypto Briefs’ coverage of fake wallet apps aimed at Ledger and Trezor users. The risky moment is often not a dramatic device compromise; it is the point when a frightened user types recovery words into a convincing form or approves a malicious action.
What Affected Trezor Buyers Should Watch for Now
Affected customers should not use links or phone numbers contained in an unexpected message. Instead, they should open a trusted browser bookmark or type Trezor’s official address manually, then use the company’s documented support path. Any request to “verify,” “sync,” “upgrade,” photograph or upload a recovery phrase should be treated as fraud.
The company says buyers who placed direct Trezor Shop orders and received a notice from [email protected] are affected. A Trezor representative also said in a public follow-up that orders through its official Amazon stores use a different fulfillment partner and are not involved. Customers uncertain about a specific order should rely on the company’s official support page, rather than replying to a message that claims to be a breach notice.
Trezor says it plans an Anonymous Delivery option with locker pickup, neutral packaging and automatic deletion of shipping identifiers after delivery, targeting the European Union by September and the United States by year-end. That is a planned mitigation, not a fix for information already exposed.
The Crypto Fear & Greed Index read 29, or Fear, on Aug. 13. It is not evidence that the breach moved the market, but it provides a cautious backdrop for an event in which the urgent reader concern is account and physical-security hygiene, not token price.
Fear & Greed Index
Aug. 13, 2026As of publication, Trezor has not disclosed an attacker identity, a cause beyond unauthorized access at ShipMonk, a financial-loss total or a confirmed phishing campaign using this data. Those are the updates worth watching. For now, the verified facts are narrower but serious: roughly 13,689 people had personal data exposed, the wallet maker says keys and devices were not compromised, and the most immediate danger is a more believable attempt to make an affected buyer surrender the one secret that matters.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | Trezor: Recent customer data exposed in shipping provider incident |
| | Trezor: Privacy policy and 90-day data retention |
| | Trezor: Scams and phishing guidance |
| | BleepingComputer: snail-mail phishing targeting Trezor and Ledger users |
| | CoinGecko: Bitcoin price and market data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
How many Trezor customers were affected by the ShipMonk breach?
Trezor reported 11,742 customers with full exposure and 1,947 with partial exposure, or approximately 13,689 customers in total. Trezor says the partial-exposure group may include older orders while it verifies the exact timeframe.
What Trezor customer data was exposed?
For the fully exposed group, Trezor lists name, email address, phone number and shipping address. The partial-exposure group had name, city and email address exposed. Trezor also says order numbers were among the data held by ShipMonk for delivery.
Were Trezor wallets, private keys or recovery phrases exposed?
Trezor says no. The company says its systems and devices were not compromised and that private keys and wallet backups were not affected. The immediate risk it identifies is more convincing phishing using exposed personal details.
What should an affected Trezor customer do?
Treat unsolicited emails, calls, texts and letters as suspicious, verify information through Trezor's official website, and never enter or share a wallet backup or recovery phrase online. Trezor says notified customers received an email from [email protected].



