Crypto World
Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers
The breach hit 11,742 customers whose names, email addresses, phone numbers, and shipping addresses were all exposed, plus 1,947 whose names, cities, and email addresses were taken.
Order numbers were included. Trezor said the records came from orders received between May 10 and August 8, 2026, and named the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal as the affected markets.
“Our systems were not compromised, and your Trezor device is secure,” the company stated, adding that hardware wallets, private keys, and wallet backups were not affected.
A 90-day data storage policy, which Trezor said it negotiated into its fulfillment partners’ terms as well, kept older orders out of the exposed set, but every affected customer was contacted individually by email.
Phishing Warning Follows Address Leak
Trezor told customers to treat any communication that demands immediate action or requests personal information as “suspicious,” to check claims against official channels, and to never enter a wallet backup on a website or share it with anyone.
Its disclosure said affected customers “could experience an increase in phishing attempts.” But it seems users found that statement cynical. “Phishing?? They have physical addresses, you imbeciles,” wrote an X user posting as Chikun, in a reply that collected about 159 likes within the hour. Another reply called the exposure “irl phishing.”
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
The phishing risk still tracks what followed a comparable incident at a rival. CryptoPotato reported that scammers used order data leaked from Ledger’s e-commerce partner Global-e to send phishing emails claiming Ledger and Trezor had merged, pushing recipients to enter 24-word recovery phrases on a fake site.
Yet Another Trezor Incident
Trezor said it is investigating and will publish updates on its blog. The company also mentioned building an Anonymous Delivery option, with neutral packaging, generic sender details, and automatic deletion of shipping identifiers.
Not an easy time for being a Trezor customer, as they have been reached through vendors twice before. Attackers sent phishing emails through a Trezor mailing list compromised at MailChimp in 2022, pointing users to lookalike download domains built to steal seed phrases.
Two years later, a breach of a third-party support ticketing portal exposed names and email addresses for roughly 66,000 users who had contacted Trezor Support since December 2021. Both of those exposed contact details, but this one exposed home addresses across multiple countries.
The post Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers appeared first on CryptoPotato.
You must be logged in to post a comment Login