Crypto World
Trezor says ShipMonk breach exposed data of 13,689 customers
Trezor has disclosed that personal information belonging to 13,689 customers was exposed after an unauthorized actor gained access to systems operated by its shipping provider ShipMonk.
Summary
- ShipMonk breach exposed personal information belonging to 13,689 Trezor customers.
- Names, emails, phone numbers, and shipping addresses were among the data accessed.
- Trezor said its systems and hardware wallets were not compromised in the incident.
- Affected customers have been warned about potentially more convincing phishing attempts.
- Trezor plans to launch Anonymous Delivery in the EU by September 2026 and the U.S. by year-end.
Trezor said in an Aug. 13 security notice that ShipMonk informed the hardware wallet maker on Aug. 10 about unauthorized access to systems containing customer order data, with an investigation into the incident still underway.
The breach affected customers who received Trezor orders between May 10 and Aug. 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said its own systems were not compromised and its hardware wallets remain secure.
Of the affected customers, 11,742 had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had partial information compromised, consisting of their names, cities and email addresses.
Order numbers were also among the information held by ShipMonk for deliveries, according to Trezor’s explanation of the incident.
ShipMonk breach exposed recent Trezor order data
ShipMonk serves as a logistics provider that stores Trezor products and handles deliveries in the U.S., U.K., and several other markets. The fulfillment company requires customer names, addresses, phone numbers, and email addresses to process shipments.
According to Trezor, the number of exposed customers was limited by its 90-day data retention policy, which it also requires fulfillment partners to follow. Customer information associated with older orders had already been deleted or anonymized and was therefore not stored in the affected ShipMonk systems.
Trezor said the 90-day period was designed to cover the full order process, including delivery, returns, refunds and product replacements. Once the period ends, purchase-related customer information is deleted or anonymized because the company no longer needs the address or phone number for fulfillment purposes.
Affected customers have been notified separately through emails sent from [email protected]. Customers who did not receive the security notification were not affected by the incident, according to the company.
ShipMonk has since secured the affected systems and strengthened its security following the breach, Trezor said. Both companies remain in contact as they work to establish how the unauthorized access occurred and determine the exact information that was accessed.
The incident represents the first time since Trezor was founded in 2013 that a breach involving the company or one of its providers has exposed customer phone numbers and shipping addresses.
“We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected,” Trezor said.
Trezor warns exposed data could support phishing attacks
Although wallet devices and Trezor’s infrastructure were unaffected, the company warned that exposed personal information could be used to create more convincing phishing attempts.
Attackers could use a customer’s name, phone number, email or home address to impersonate Trezor, a cryptocurrency exchange or a bank. The company said fraudulent approaches could arrive through emails, phone calls or physical letters.
Such attacks have previously targeted hardware wallet owners using personal information and official-looking communications. In February, crypto.news reported on fake letters sent to Trezor and Ledger customers that directed recipients to phishing websites through QR codes.
The letters told recipients that they needed to complete an authentication or transaction check and attempted to create urgency by warning about possible problems with wallet functionality. The linked phishing pages requested 12-, 20- or 24-word recovery phrases, which would give attackers control over a wallet once submitted.
Physical letters present a particular concern when attackers already possess a victim’s mailing details. An April 2025 Ledger phishing campaign similarly involved fraudulent letters carrying Ledger branding, a business address and individual reference numbers.
Recipients in that campaign were instructed to scan a QR code and provide their 24-word recovery phrase under the claim that a critical security update was required.
Trezor has told customers affected by the ShipMonk breach to treat communications demanding immediate action or personal information with suspicion. It also advised users to verify messages against its official communications and never provide a wallet backup through a website or to another person.
Previous Trezor incidents have also led to phishing warnings
Trezor has dealt with customer information exposure through third-party services before, although the company said the ShipMonk incident was its first involving leaked phone numbers and shipping addresses.
In January 2024, an unauthorized party accessed a third-party support ticket portal used by Trezor, potentially exposing contact information belonging to about 66,000 customers who had interacted with the support team since late 2021.
The company notified affected contacts at the time and said digital assets had not been compromised. The incident involved the external support system rather than Trezor hardware wallets.
Another phishing method emerged in June 2025 when attackers abused Trezor’s contact form by submitting support requests using targeted users’ email addresses. The process triggered legitimate automated replies from Trezor’s system, making the resulting phishing communications appear more credible.
Trezor said at the time that its email infrastructure had not been breached and that the contact form remained secure. Attackers instead exploited the support workflow to make fraudulent messages appear connected to legitimate correspondence.
Hardware security has separately remained under scrutiny. In June, Trezor and Tropic Square disclosed a chip flaw affecting the TROPIC01 Secure Element used in the Trezor Safe 7 after researchers from Ledger Donjon found the weakness during an independent audit.
Ledger Donjon used laser fault injection under laboratory conditions to extract some chip secrets and bypass firmware signature checks. Trezor said the attack required physical access and specialized equipment, while two other independent security layers continued to protect access to the wallet. Users were not required to take action.
The ShipMonk incident, by comparison, involved order information held by a fulfillment provider rather than the hardware or software responsible for securing private keys.
Trezor plans anonymous delivery option
Following the latest disclosure, Trezor also detailed ways customers can reduce the amount of personal information connected to future hardware wallet purchases.
The company recommended using an email address that is not linked to a customer’s primary identity and suggested cryptocurrency payments as an alternative to credit cards. Where available, customers can also use a P.O. Box to reduce the exposure of their home address, although identification requirements and postal service records may still apply.
Trezor is also preparing an Anonymous Delivery service designed to reduce the customer information retained during hardware wallet shipments.
Under the planned system, orders would use a dedicated checkout process, locker collection, neutral packaging and generic sender information. Shipping identifiers would then be automatically deleted after delivery.
Trezor said it plans to make Anonymous Delivery available in the European Union by September 2026, followed by a U.S. rollout by the end of 2026.
You must be logged in to post a comment Login